[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/wireshark-quiz-icedid-answers/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/ "Learning Hub")
* [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/ "Cybersecurity Tutorials")  
  [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)

# Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 13 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Brad Duncan](https://unit42.paloaltonetworks.com/author/brad-duncan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:May 30, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)
  * [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/)
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/)
  * [BokBot](https://unit42.paloaltonetworks.com/tag/bokbot/)
  * [IcedID](https://unit42.paloaltonetworks.com/tag/icedid/)
  * [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/)
  * [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/)
  * [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/?pdf=download&lg=en&_wpnonce=0070e94fe3 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/?pdf=print&lg=en&_wpnonce=0070e94fe3 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Cold%20as%20Ice:%20Answers%20to%20Unit%2042%20Wireshark%20Quiz%20for%20IcedID&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-icedid-answers%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-icedid-answers%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-icedid-answers%2F&title=Cold%20as%20Ice:%20Answers%20to%20Unit%2042%20Wireshark%20Quiz%20for%20IcedID "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-icedid-answers%2F&text=Cold%20as%20Ice:%20Answers%20to%20Unit%2042%20Wireshark%20Quiz%20for%20IcedID "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-icedid-answers%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Cold%20as%20Ice:%20Answers%20to%20Unit%2042%20Wireshark%20Quiz%20for%20IcedID%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwireshark-quiz-icedid-answers%2F "Share in Mastodon")

## Executive Summary

Our introductory blog [Cold as Ice: Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/) provides a packet capture (pcap) from an IcedID infection in April 2023. This blog provides the answers. Also known as Bokbot, IcedID is well-established Windows-based malware that can lead to ransomware. Reviewing the pcap provides an opportunity to analyze IcedID infection traffic.

If you would like to view this quiz without answers, please see [our previous blog introducing the standalone quiz](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/).

Palo Alto Networks customers are protected from IcedID and other malware through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and our [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions) that include [WildFire](https://www.paloaltonetworks.com/network-security/wildfire), [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention) and [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering).

| **Related Unit 42 Topics** | [**pcap**](https://unit42.paloaltonetworks.com/tag/pcap/)**,** [**Wireshark**](https://unit42.paloaltonetworks.com/tag/Wireshark/)**,** [**Wireshark Tutorial**](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/), **[IcedID](https://unit42.paloaltonetworks.com/tag/icedid/), [BokBot](https://unit42.paloaltonetworks.com/tag/bokbot/)** |
|----------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## Scenario, Requirements and Quiz Material

Traffic for this quiz occurred in an Active Directory (AD) environment during April 2023. The infection is similar to previous IcedID activity [tweeted by Unit 42 in March 2023](https://twitter.com/Unit42_Intel/status/1639371567900798977). Details of the Local Area Network (LAN) environment for the pcap follow.

* LAN segment range: 10.4.19\[.\]0/24 (10.4.19\[.\]1 through 10.4.19\[.\]255)
* Domain: boogienights\[.\]live
* Domain controller IP address: 10.4.19\[.\]19
* Domain controller hostname: WIN-GP4JHCK2JMV
* LAN segment gateway: 10.4.19\[.\]1
* LAN segment broadcast address: 10.4.19\[.\]255

This quiz requires Wireshark, and we recommend using the [latest version of Wireshark](https://www.wireshark.org/download.html), since it has more features, capabilities and bug fixes over previous versions.

We also recommend readers customize their Wireshark display to better analyze web traffic. [A list of tutorials and videos is available](https://unit42.paloaltonetworks.com/wireshark-workshop-videos/). As always, we recommend using Wireshark in a non-Windows environment like BSD, Linux or macOS when analyzing malicious Windows-based traffic.

To obtain the pcap, [visit our GitHub repository](https://github.com/pan-unit42/Wireshark-quizzes/), download the April 2023 ZIP archive and extract the pcap. Use *infected* as the password to unlock the ZIP archive.

## Quiz Questions

For this IcedID infection, we ask participants to answer the following questions previously described in our [standalone quiz post](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/):

* What is the date and time in UTC the infection started?
* What is the IP address of the infected Windows client?
* What is the MAC address of the infected Windows client?
* What is the hostname of the infected Windows client?
* What is the user account name from the infected Windows host?
* Is there any follow-up activity from other malware?

## Quiz Answers

The AD environment for this pcap contains three Windows clients, but only one was infected with IcedID.

Answers for this Wireshark quiz follow.

* Malicious traffic for this infection started on April 19, 2023, at 15:31 UTC.
* Infected Windows client IP address: 10.4.19\[.\]136
* Infected Windows client MAC address: 14:58:d0:2e:c5:ae
* Infected Windows client hostname: DESKTOP-SFF9LJF
* Infected Windows client user account name: csilva
* Follow-up activity: BackConnect traffic

## Pcap Analysis: IcedID Chain of Events

To understand IcedID network traffic, you should understand the chain of events for an IcedID infection. A flow chart illustrating this chain of events is shown in Figure 1.
![Image 1 is a flowchart of the chain of events in the April 2023 IcedID infection. It starts with email and or web-based delivery methods, continues to the IcedID installer, HTTP traffic for the gzip binary, malware created from that binary, and then command and control traffic from the IcedID infection. The initial follow-up activity can include Cobalt sStrike, VNC traffic, and BackConnect.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/Wireshark-Traffic-Graph-Revised.png) Figure 1. Flowchart for chain of events in the April 2023 IcedID infection.

Most IcedID infections use a [standard variant](https://www.proofpoint.com/us/blog/threat-insight/fork-ice-new-era-icedid) of IcedID. These infections typically use an EXE or DLL that acts as an installer. This installer generates an unencrypted HTTP GET request that retrieves a gzip-compressed binary. The installer then converts this binary into malware used for a persistent IcedID infection.

The newly created, persistent IcedID generates HTTPS traffic to communicate with command and control (C2) servers. The C2 activity can lead to [BackConnect](https://www.netresec.com/?page=Blog&month=2022-10&post=IcedID-BackConnect-Protocol) traffic, [Cobalt Strike](https://www.cybereason.com/blog/threat-analysis-report-all-paths-lead-to-cobalt-strike-icedid-emotet-and-qbot) and [Virtual Network Computing (VNC)](https://blog.nviso.eu/2023/03/20/icedids-vnc-backdoors-dark-cat-anubis-keyhole/) activity.

If the infected host is part of a high-value environment, an IcedID infection would likely [lead to ransomware](https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/).

## Pcap Analysis: Infection Vector

Using Wireshark [customized from our tutorials](https://unit42.paloaltonetworks.com/wireshark-workshop-videos/), apply a basic web filter to see if anything stands out. Review the results in your column display. Look for unencrypted HTTP traffic over TCP port 80 directly to an IP address without an associated domain. This is a common characteristic in the chain of events for various malware infections.

At 15:31:08 UTC, the host at 10.4.19\[.\]136 generated an HTTP GET request to hxxp://80.77.25\[.\]175/main.php as shown below in Figure 2.
![Image 2 is a screenshot of suspicious HTTP traffic in Wireshark that goes directly to an IP address, which is highlighted with an arrow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-2-1.jpeg) Figure 2. Suspicious HTTP traffic directly to an IP address shown in Wireshark.

Follow the TCP stream for this HTTP GET request, as shown in Figure 3. This should generate a window for TCP stream 32, as shown in Figure 4.
![Image 3 shows the menu selection to follow the TCP stream for the suspicious HTTP GET request.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-3-1.jpeg) Figure 3. Following TCP stream for suspicious HTTP GET request. ![Image 4 is the TCP stream window in Wireshark. Indicated with two arrows is the first line of the HTTP GET request and highlighted by the black box is the location.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-4.jpeg) Figure 4. TCP stream for the suspicious HTTP GET request and response.

Figure 4 reveals HTTP request headers that contain a User-Agent string ending with Edg/112.0.1722.48. This string indicates the traffic was likely generated by the Microsoft Edge browser. However, web traffic generated by malware can spoof different User-Agent strings, and some [browser extensions also have this ability](https://chrome.google.com/webstore/detail/user-agent-switcher-for-c/djflhoibgkdhkhhcedjiklpkjnoahfmg), so we cannot be certain this was actually Microsoft Edge.

The HTTP response headers in Figure 4 show a 302 code, redirecting traffic to the following URL:

hxxps://firebasestorage.googleapis\[.\]com/v0/b/serene-cathode-377701.appspot.com/o/XSjwp6O0pq%2FScan\_Inv.zip?alt=media\&token=a716bdce-1373-44ed-ae89-fdabafa31c61

This Firebase Storage URL has been reported as malicious by at least seven security vendors [on VirusTotal](https://www.virustotal.com/gui/url/bb5b6a8153c5ee763749b8e06a2ae1c2f8b51a3c041c84064c7cd82aba353362/detection), and it [appears in URLhaus](https://urlhaus.abuse.ch/url/2614322/) tagged as IcedID. Fortunately, Google has taken the URL offline, and it is no longer active.

To further refine our search, add the client's IP address 10.4.19\[.\]136 to the basic web filter as shown below in Figure 5. This reveals HTTPS traffic to firebasestorage.googleapis\[.\]com shortly after traffic to the initial URL at hxxp://80.77.25\[.\]175/main.php.

![Image 5 is a screenshot of the HTTPS traffic to firebasestorage.googleapis\[.\]com after the initial suspicious URL. Highlighted in green in the screenshot is the command to insert into Wireshark. Two arrows indicate the request and the suspicious URLs.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-5.jpeg) Figure 5. HTTPS traffic to firebasestorage.googleapis\[.\]com after the initial suspicious URL. Follow the TCP stream for the initial frame showing fire in the Wireshark column display. The TCP stream reveals 273 KB of data sent from the server to the Windows host, as shown below in Figure 6. This indicates a file might have been sent to the Windows host.

![Image 6 is the TCP stream window showing the 275 kB of data sent from firebasestorage.googleapis\[.\]com to the Windows host. This is highlighted by an arrow in a menu that shows the entire conversation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-6.jpeg) Figure 6. TCP stream showing 275 KB of data sent from firebasestorage.googleapis\[.\]com to the Windows host. While the Firebase Storage URL is [tagged as IcedID on URLhaus](https://urlhaus.abuse.ch/url/2614322/), this only indicates a distribution method for the IcedID installer. Based on this pcap, the victim opened a link that led to the Firebase Storage URL, and that URL delivered a file for an IcedID installer.

The [URLhaus entry for this Firebase Storage URL](https://urlhaus.abuse.ch/url/2614322/) reveals the ZIP archive it previously hosted, as shown in Figure 7.
![Image 7 is a screenshot of the URLhaus entry for the firebasestorage URL. The screenshot shows the payload delivery, when it was first seen, the file name and file type, and the signature, which is IcedID.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-7.jpeg) Figure 7. URLhaus entry for our firebasestorage URL shows it delivered a zip archive.

The ZIP archive was [submitted to Malware Bazaar](https://bazaar.abuse.ch/sample/fc96c893a462660e2342febab2ad125ce1ec9a90fdf7473040b3aeb814ba7901/). The archive is password-protected with the ASCII string *1235* , and it contains a file named Scan\_Inv.exe. This Windows executable file is an IcedID installer.

## Pcap Analysis: IcedID Traffic

An IcedID loader first generates an unencrypted HTTP GET request over TCP port 80 to a domain using GET / without any further URL. This returns a gzip binary used by the installer to create the persistent malware on the victim's host.

To find the gzip binary, use the same basic web filter with the victim's IP address noted earlier in Figure 5. Scroll down to an HTTP GET request to skigimeetroc\[.\]com at 15:35:39 UTC and follow the TCP stream as shown below, in Figure 8.
![Image 8 is a screenshot of the menu selection to follow the TCP stream for IcedID installers initial HTTP GET request. Highlighted in green is the filter to enter into Wireshark.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-8.jpeg) Figure 8. Following the TCP stream for IcedID installer's initial HTTP GET request.

This is TCP stream 53 from the pcap, as shown below in Figure 9. The HTTP request headers for traffic generated by the IcedID installer have no User-Agent string. Note the cookie sent in the request headers in Figure 9.
![Image 9 is the TCP stream window in Wireshark. Highlighted with a black box is the cookie data. Highlighted with an arrow is the gzip binary.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-9.jpeg) Figure 9. HTTP GET request generated by the IcedID installer.

The cookie line follows:

Cookie: \_\_gads=422998217:1:1808:131; \_gid=A0CA96894E9D; \_u=4445534B544F502D534646394C4A46:6373696C7661:46353431423635424230383346354633; \_\_io=21\_1181811818\_1193560798\_2439418475; \_ga=1.591597.1635208534.1022; \_gat=10.0.22621.64

[Cookie parameters](https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-gootloader-and-icedid) for the HTTP GET request caused by this IcedID installer follow:

* \_\_gads= IcedID campaign identifier and information from the infected host.
* \_gid= Value calculated using MAC address of the infected host.
* \_u= ASCII text representing hex values of the victim's hostname, Windows user account name and another undetermined value.
* \_\_io= Domain identifier from the infected host's [security identifier (SID)](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-identifiers#security-identifier-architecture).
* \_ga= Information based on the infected host's CPU.
* \_gat= Windows version. For example, 10.0.22621.64 is an identifier for 64-bit Windows 11 version 22H2 and 10.0.19045.64 is an identifier for 64-bit Windows 10 version 22H2.

These cookie parameters are unique to IcedID infections. You can identify this traffic as IcedID without understanding the values. However, the \_u= parameter reveals the victim's hostname and Windows user account name. This information is very useful for our investigation. These hex values translate to a hostname of DESKTOP-SFF9LJF and a Windows user account name of csilva, as shown below in Figure 10.
![Image 10 shows two hex value translations. The hex value highlighted in yellow translates to DESKTOP-SFF9LJF. The hex value highlighted in blue translates to csilva.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-10.jpeg) Figure 10. Using the \_u= cookie parameter to determine the victim's hostname and Windows user account name.

After retrieving the gzip binary, an IcedID installer creates persistent IcedID malware that takes over the infection. The infected Windows host then starts generating HTTPS traffic to IcedID C2 servers.

These C2 servers use different domain names and IP addresses than the initial domain contacted by the IcedID installer. IcedID's HTTPS C2 traffic starts within a minute or two after the installer retrieves the gzip binary, and this activity uses at least two domains with random alphabetic names.

Our pcap reveals HTTPS traffic from the infected host to two domains after skigimeetroc\[.\]com at 15:35:39 UTC. These HTTPS C2 servers are askamoshopsi\[.\]com on 104.168.53\[.\]18 and skansnekssky\[.\]com on 217.199.121\[.\]56.

To find these servers, use the same basic web filter with the victim's IP address noted earlier in Figure 5. HTTPS traffic starting at 15:36:41 UTC reveals these domains, as shown below in Figure 11.
![Image 11 is a screenshot of the Wireshark traffic for the command and control IcedID servers. Highlighted with a black box is the IcedID installer that retrieve the gzip binary.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-11.png) Figure 11. HTTPS C2 traffic after HTTP request by the IcedID installer.

Both C2 servers at askamoshopsi\[.\]com and skansnekssky\[.\]com use self-signed certificates for their HTTPS traffic. Self-signed certificates for HTTPS traffic will generate warnings about potential security risks when the site is viewed in any modern web browser.

Why do web browsers display warnings about websites that use self signed certificates? Because these are not validated by a [Certificate Authority](https://www.ssl.com/faqs/what-is-a-certificate-authority/). Criminals can generate self-signed certificates that impersonate an existing company, or they can use generic values for the certificate issuer. Without a validated certificate, web browsers cannot be sure a website is what it says it is.

Figure 12 shows what the server at askamoshopsi\[.\]com looked like when we attempted to view it with the Firefox web browser. This warning allows users to view the server's self-signed certificate.

![Image 12 is two screenshots of Mozilla Firefox windows, showing a warning for the potential security risk of the invalid certificate. It also shows the certificate for the localhost.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-12.jpeg) Figure 12. Attempting to view the web server at askamoshopsi\[.\]com using Firefox. As shown above in Figure 12, the certificate uses values like Internet Widgits Pty Ltd for the issuer's Organization name and Some-State for the State/Province name. Values for self-signed certificates used by IcedID C2 servers are the same default values seen when [using OpenSSL to create a certificate](https://www.openssl.org/docs/man1.1.1/man1/openssl-req.html) in Xubuntu as shown below in Figures 13 and 14.

![Image 13 is the Xubuntu terminal x509 certificate creation for a web server using OpenSSL.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-13.jpeg) Figure 13. Creating an x509 certificate for a web server using OpenSSL in Xubuntu. ![Image 14 is the Xubuntu terminal default values for the x509 certificate creation. Highlighted with arrows are the country name two letter code, which is Australia, the state, or province, name, and the organization name, which is Internet Widgets Pty Ltd.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-14.jpeg) Figure 14. Default values when creating an x509 certificate for a web server using OpenSSL in Xubuntu.

Since Internet Widgits Pty Ltd is a default value for a self-signed certificate in HTTPS traffic, and this value is sometimes seen in C2 traffic for malware. This should be more closely examined if it's found when investigating a suspected malware infection. We can easily check any pcap for this value using the following Wireshark filter:

x509sat.uTF8String eq "Internet Widgits Pty Ltd"

The results from our pcap reveal the same IP addresses used by IcedID C2 servers for askamoshopsi\[.\]com at 104.168.53\[.\]18 and skansnekssky\[.\]com at 217.199.121\[.\]56. Expand the frame details for any of the results to find the same certificate issuer data, as shown in Figure 15.
![Image 15 is a Wireshark screenshot. Highlighted in green is the command to put into the search bar. The results, highlighted by arrows, are the transport layer security, the certificate, including size, and the issuer of the certificate. Highlighted in a black box are the IDs that showed in the Xubuntu terminal.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-15.jpeg) Figure 15. Self-signed certificate by IcedID C2 servers using Internet Widgits Pty Ltd as the Organization name shown in Wireshark.

This certificate data is not unique to IcedID. The same values for self-signed certificates are also seen in HTTPS C2 traffic by other malware families like [Bumblebee](https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/).

## Pcap Analysis: BackConnect Traffic

Undetected IcedID infections lead to follow-up activity like [BackConnect](https://www.netresec.com/?page=Blog&month=2022-10&post=IcedID-BackConnect-Protocol) traffic.

For the past several months, BackConnect traffic caused by IcedID was easy to detect because it occurred over TCP port 8080. However, as early as April 11, 2023, BackConnect activity for IcedID [changed to TCP port 443](https://twitter.com/Unit42_Intel/status/1645851799427874818), making it harder to find.

This BackConnect activity from IcedID [Unit 42 tweeted on April 11, 2023](https://twitter.com/Unit42_Intel/status/1645851799427874818) used an IP address of 193.149.176\[.\]100 over TCP port 443. Filter for that IP address in Wireshark and combine it with tcp.flags eq 0x0002 as shown below, in Figure 16. This reveals the beginning of three streams.
![Image 16 is a Wireshark command, highlighted in green, showing how to filter in Wireshark for the BackConnect traffic in the packet capture.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-16.jpeg) Figure 16. Filtering in Wireshark for BackConnect traffic in our pcap.

Follow the TCP stream for the first result, which is TCP stream 950. This stream reveals encoded or otherwise encrypted TCP traffic, as shown in Figure 17.
![Image 17 is a TCP stream terminal window in Wireshark showing the BackConnect activity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-17.jpeg) Figure 17. The first TCP stream for BackConnect activity.

Go back to the Wireshark filter used to reveal the TCP streams to 193.149.176\[.\]100. Follow the TCP stream for the second frame in the results, which is TCP stream 951. This reveals encoded or encrypted data followed by a command to reveal all hosts under the domain controller for boogienights\[.\]live as shown below, in Figure 18.
![Image 18 is a TCP stream terminal window in Wireshark showing the BackConnect traffic with a command to and the results enumerating the Active Directory environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-18.jpeg) Figure 18. BackConnect traffic with a command to and results enumerating the victim's AD environment.

The response to this command enumerates the victim's AD environment, showing three clients logged in to the domain:

* DESKTOP-JAL4D68
* DESKTOP-RETP4BU
* DESKTOP-SFF9LJF

Go back to the Wireshark filter used to reveal the TCP streams to 193.149.176\[.\]100. Follow the TCP stream for the last frame in the results, which is TCP stream 953. This lists disk drives on the victim client, and it provides a directory listing for each of these drives, as shown below in Figure 19.

The C:\\ drive is the victim's system drive. Z:\\ is likely a mapped drive from a server's shared directory that does not contain any files.
!["Image 19 is a TCP stream terminal window in Wireshark showing the BackConnect traffic. A highlighted black box shows where the attacker sends a DISK command. The victim returns the disk drive list. The attacker then changes the directory to the Z:\\ drive and lists its contents. This drive is empty. The second black box highlights where the attacker changes the directories to the C:\\ drive and lists its contents. This is the victim’s system drive. It contains files and directories normally seen on a Windows host. This screenshot also shows the entire conversation size which is 796 bytes."](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-19.png) Figure 19. BackConnect traffic showing contents of the victim's system drive and mapped drive.

Previous IcedID infections reveal this threat can use BackConnect traffic to load and run Cobalt Strike. We tweeted about [one such case from March 24, 2023](https://twitter.com/Unit42_Intel/status/1639371567900798977). However, this pcap does not contain any indicators of Cobalt Strike.

Previous IcedID infections also reveal this threat can generate VNC traffic over the same IP address used by BackConnect traffic. This happened during the [same IcedID infection from March 24, 2023](https://www.malware-traffic-analysis.net/2023/03/24/index.html).

## Pcap Analysis: Victim Details

The common internal IP address for the malicious traffic we have reviewed is 10.4.19\[.\]136. This is our victim's IP address. To find the Windows user account name, filter on that IP address and kerberos.CNameString as shown in Figure 20.
![Image 20 is a Wireshark screenshot highlighting the CNameString column, and the outcome of selecting “apply as column” from the menu. Highlighted in green is the command to filter to do this. Highlighted by arrows are the Windows account user name for the infected Windows host.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-20.jpeg) Figure 20. Finding the Windows user account name for our infected Windows host.

In some cases, lightweight directory access protocol (LDAP) might also provide the full name of the user. Use the following Wireshark filter:

ldap.AttributeDescription == "givenName"

This should provide four frames in our column display. Select any of them and expand the frame details until you find the user's full name, Cornelius Silva, as shown below in Figure 21.
![Image 21 is a Wireshark screenshot showing how to filter to find the victim’s full name from LDAP traffic. Highlighted by arrows are the names.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-21.jpeg) Figure 21. Finding the victim's full name from LDAP traffic.

Perhaps the easiest way to find a victim's hostname in Wireshark is to combine the victim's IP address with a search for ip contains "DESKTOP-" as shown below, in Figure 22. Several results in the info column show Host Announcement DESKTOP-SFF9LJF sent by our infected Windows host at 10.4.19\[.\]136.
![Image 22 is a Wireshark screenshot showing how to filter to find the Windows hostname in Wireshark. Highlighted in green is the filter to use.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-22.jpeg) Figure 22. Finding the Windows hostname in Wireshark.

To find the victim's MAC address, just correlate the IP address to the host's MAC address in any of the frame details windows, as shown below in Figure 23.
![Image 23 is a screenshot where, highlighted, shows the victim’s MAC address with its associated IP address.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128267-23.jpeg) Figure 23. Correlating the victim's MAC address with its associate IP address.

## Conclusion

This blog provides answers and analysis for our Unit 42 Wireshark quiz featuring an IcedID infection from April 2023. IcedID is important to identify and stop, because it is a [known vector for ransomware infections](https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/).

Many organizations lack access to full packet capture in their IT environment. As a result, security professionals might lack experience reviewing IcedID and other malware traffic. Training material like this Wireshark quiz can help. Pcap analysis is a useful skill that helps us better understand malicious activity.

You can also read the original post, without answers, from our [standalone quiz post](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/).

Palo Alto Networks customers are protected from IcedID and other malware through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and our [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions) that include [WildFire](https://www.paloaltonetworks.com/network-security/wildfire), [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention) and [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering).

If you think you might have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

Traffic from the pcap related to the IcedID infection:

* hxxp://80.77.24\[.\]175/main.php
* hxxps://firebasestorage.googleapis\[.\]com/v0/b/serene-cathode-377701.appspot.com/o/XSjwp6O0pq%2FScan\_Inv.zip?alt=media\&token=a716bdce-1373-44ed-ae89-fdabafa31c61
* 192\.153.57\[.\]223:80 - hxxp://skigimeetroc\[.\]com/
* 104\.168.53\[.\]18:443 - askamoshopsi\[.\]com - HTTPS traffic
* 217\.199.121\[.\]56:443 - skansnekssky\[.\]com - HTTPS traffic
* 193\.149.176\[.\]100:443 - BackConnect traffic

Files associated with traffic from this IcedID infection:

* SHA256 hash: fc96c893a462660e2342febab2ad125ce1ec9a90fdf7473040b3aeb814ba7901
* File size: 262,343 bytes
* Filename: Scan\_Inv.zip
* File description: Password-protected ZIP archive hosted on Firebase Storage URL
* Password: 1235
* [MalwareBazaar Database sample](https://bazaar.abuse.ch/sample/fc96c893a462660e2342febab2ad125ce1ec9a90fdf7473040b3aeb814ba7901/)
* SHA256 hash: bd24b6344dcde0c84726e620818cb5795c472d9def04b259bf9bff1538e5a759
* File size: 333,408 bytes
* Filename: Scan\_Inv.exe
* File description: Windows executable file for IcedID installer
* [MalwareBazaar Database sample](https://bazaar.abuse.ch/sample/bd24b6344dcde0c84726e620818cb5795c472d9def04b259bf9bff1538e5a759/)

## Additional Resources

* [Wireshark Tutorial: Wireshark Workshop Videos Now Available](https://unit42.paloaltonetworks.com/wireshark-workshop-videos/) -- Unit 42, Palo Alto Networks
* [Unit 42 Wireshark Quiz, January 2023](https://unit42.paloaltonetworks.com/january-wireshark-quiz/) -- Unit 42, Palo Alto Networks
* [Answers to January 2023 Unit 42 Wireshark Quiz](https://unit42.paloaltonetworks.com/january-wireshark-quiz-answers/) -- Unit 42, Palo Alto Networks
* [Unit 42 Wireshark Quiz, February 2023](https://unit42.paloaltonetworks.com/feb-wireshark-quiz/) -- Unit 42, Palo Alto Networks
* [Answers to February 2023 Unit 42 Wireshark Quiz](https://unit42.paloaltonetworks.com/feb-wireshark-quiz-answers/) -- Unit 42, Palo Alto Networks
* [Finding Gozi: Unit 42 Wireshark Quiz, March 2023](https://unit42.paloaltonetworks.com/march-wireshark-gozi/) -- Unit 42, Palo Alto Networks
* [Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/) -- Unit 42, Palo Alto Networks
* [Unit 42 tweet, Jan. 1, 2023](https://twitter.com/Unit42_Intel/status/1613710507638235136) -- IcedID infection leads to Cobalt Strike
* [Unit 42 tweet, Feb. 8, 2023](https://twitter.com/Unit42_Intel/status/1623707361184477185) -- Cobalt Strike from an IcedID infection
* [Unit 42 tweet, Feb. 13, 2023](https://twitter.com/Unit42_Intel/status/1625218084288987136) -- Fake software page leads to IcedID
* [Unit 42 tweet, Feb. 24, 2023](https://twitter.com/Unit42_Intel/status/1630265343879835656) -- IcedID to BackConnect traffic to Cobalt Strike
* [Unit 42 tweet, March 24, 2023](https://twitter.com/Unit42_Intel/status/1639371567900798977) -- IcedID to BackConnect traffic to Cobalt Strike
* [Unit 42 tweet, April 11, 2023](https://twitter.com/Unit42_Intel/status/1645851799427874818) -- IcedID to BackConnect traffic changes TCP port
* [Fork in the Ice: The New Era of IcedID](https://www.proofpoint.com/us/blog/threat-insight/fork-ice-new-era-icedid) -- Proofpoint
* [IcedID BackConnect Protocol](https://www.netresec.com/?page=Blog&month=2022-10&post=IcedID-BackConnect-Protocol) -- Netresec
* [Inside the IcedID BackConnect Protocol](https://www.team-cymru.com/post/inside-the-icedid-backconnect-protocol) -- Team Cymru
* [Threat Analysis Report: All Paths Lead to Cobalt Strike - IcedID, Emotet at Qbot](https://www.cybereason.com/blog/threat-analysis-report-all-paths-lead-to-cobalt-strike-icedid-emotet-and-qbot) -- Cybereason
* [IcedID \& Qakbot's VNC Backdoors: Dark Cat, Anubis \& Keyhole](https://blog.nviso.eu/2023/03/20/icedids-vnc-backdoors-dark-cat-anubis-keyhole/) -- NVISO Labs
* [Malicious ISO File Leads to Domain Wide Ransomware](https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/) - The DFIR Report
  Back to top

### Tags

* [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/ "banking trojans")
* [BokBot](https://unit42.paloaltonetworks.com/tag/bokbot/ "BokBot")
* [IcedID](https://unit42.paloaltonetworks.com/tag/icedid/ "IcedID")
* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")
* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")
* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Cold as Ice: Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/ "Cold as Ice: Unit 42 Wireshark Quiz for IcedID")

### Table of Contents

* 

### Related Articles

* [LDAP Enumeration: Unveiling the Double-Edged Sword of Active Directory](https://unit42.paloaltonetworks.com/lightweight-directory-access-protocol-based-attacks/ "article - table of contents")
* [No Way to Hide: Uncovering New Campaigns from Daily Tunneling Detection](https://unit42.paloaltonetworks.com/detecting-dns-tunneling-campaigns/ "article - table of contents")
* [Wireshark Tutorial: Exporting Objects From a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/ "article - table of contents")

## Related Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
