Researchers linked a Chile-geolocated IP address to administration of IcedID (also known as BokBot) infrastructure, tying it to the 216.73.159.0/24 netblock and to active BackConnect and Loader systems used by the malware. The IP also communicated with a Netherlands-hosted server serving two IcedID-associated domains, and its activity showed an operational pause from mid-December 2022 to late January 2023 followed by a shift from WireGuard to OpenVPN. Investigators said the node was more likely used for infrastructure management, development, or testing than for victim-facing command-and-control, and noted browsing activity to DNS, privacy, Tor, and services linked to the Conti and LockBit ecosystems.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Team Cymru observed the Chilean IP connecting to 168.100.8.93:443 beginning on 27 January 2023 and continuing daily through the time of writing. The destination hosted two domains assessed as matching current IcedID naming conventions.
When activity resumed on 26 January 2023, access to the Chilean IP shifted from WireGuard VPN to OpenVPN. Researchers noted they had previously seen both VPN technologies used in IcedID BackConnect infrastructure management.
Team Cymru observed a gap in activity from the Chilean IP used in IcedID infrastructure management beginning on 12 December 2022. The pause aligned with timelines previously seen across IcedID Bot, Loader, and BackConnect infrastructure.
Researchers identified svoykbragudern[.]com as another IcedID-linked domain resolving to 168.100.8.93. The domain was registered on 18 November 2022.
Researchers identified neonmilkustaers[.]com as an IcedID-linked domain resolving to 168.100.8.93. The domain was registered on 9 November 2022.
The Team Cymru reference states that IcedID, also known as BokBot, began in early 2017 as a banking trojan before later evolving into a dropper associated with follow-on malware and ransomware activity.
The same 0x0d4y analysis released defender-focused content including an Elastic EQL sequence rule, a YARA rule for the x64 DLL stager, a Suricata signature keyed on the __gads cookie parameter, and a Python configuration extractor.
A 0x0d4y blog post analyzed a lightweight x64 IcedID second-stage DLL injected into svchost.exe, documenting a changed configuration decryption routine and recovering the C2 hostname podiumstrtss.com.
Team Cymru reported a newly observed IP geolocated to Chile that communicated with active IcedID BackConnect and Loader infrastructure, and assessed it was likely used for administration, development, or testing rather than victim-facing C2.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
0x0d4y.blog
Open sourceteam-cymru.com
Open sourcechuongdong.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.