How to Identify IcedID Network Traffic

#IcedID #CapLoader #Periodicity #GzipLoader #a0e9f5d64349fb13191bc781f81f42e1 #ec74a5c51106f0419184d0dd08fb05bc

Brad Duncan published IcedID (Bokbot) from fake Microsoft Teams page earlier this week. In this video I take a closer look at the PCAP file in that blog post. The video cannot be played in your browser. Note: This video was recorded in a Windows Sandbox to minimize the risk of infecting the host PC[...]

Read the full writeup in the blog post How to Identify IcedID Network Traffic