Security researchers detailed a lightweight method for identifying IcedID command-and-control infrastructure without relying on full malware reverse engineering, using a distinctive self-signed TLS certificate repeatedly found on the malware’s servers. The certificate commonly carries issuer and subject values including CN=localhost, C=AU, ST=Some-State, and O=Internet Widgits Pty Ltd, allowing defenders to search internet-wide scan data for likely matches and rapidly narrow candidate hosts tied to the banking trojan.
The infrastructure was then validated by reproducing IcedID’s certificate verification logic, in which the malware hashes the certificate public key with FNV-1a 32-bit and compares the result to the certificate serial number, sometimes after XOR with 0x384A2414. Using that process, researchers confirmed 52 IcedID servers and found the infrastructure commonly exposed ports 443, 80, and 22, frequently ran Debian and nginx, and was concentrated in Romania, the United States, and Germany; related reporting on IcedID and its loader activity underscores the malware’s continued use in credential theft and banking-focused intrusions.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Netresec analyzed an IcedID infection chain delivered through a fake Microsoft Teams download page and published network-based indicators including the C2 IP, domains, certificate fingerprints, and JA3/JA3S values. The analysis highlighted that IcedID beacons to command-and-control infrastructure at five-minute intervals and noted the malware's custom BackConnect capability for VNC, file management, and reverse shell access.
Elastic Security Labs combined Censys certificate searches, Check Point’s TLS validation logic, and JARM/JA3S fingerprinting to identify 113 candidate IPs tied to IcedID infrastructure. As of October 14, 2022, the researchers confirmed 103 of those IPs as IcedID command-and-control servers.
Team Cymru analyzed multiple IcedID campaigns from September 2022 and found that Stage 1 C2 domains, previously parked for weeks before use, began being registered only a few days before campaigns around 22 September 2022. The report also noted mid-to-late September anomalies including some reuse of domains or IPs and documented delivery chains such as password-protected ZIP, ISO, and LNK-based execution.
The IcedID banking malware family, also known as BokBot, first emerged in September 2017. It was described as banker malware with capabilities including browser hooking, credential theft, man-in-the-middle proxy setup, and a VNC module.
Check Point researchers used distinctive self-signed TLS certificate fields and IcedID's certificate-validation logic to hunt for command-and-control infrastructure. They narrowed internet-wide search results to 52 servers they assessed as part of IcedID C2 infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 98 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
netresec.com
Open sourceelastic.co
Open sourceteam-cymru.com
Open sourceresearch.checkpoint.com
Open sourceblog.group-ib.com
Open sourcebinarydefense.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.