diff --git a/TA551/2020-08-31-TA551-IOCs-for-IcedID.txt b/TA551/2020-08-31-TA551-IOCs-for-IcedID.txt index 55ce9aed..ee236ff5 100644 --- a/TA551/2020-08-31-TA551-IOCs-for-IcedID.txt +++ b/TA551/2020-08-31-TA551-IOCs-for-IcedID.txt @@ -54,7 +54,7 @@ AT LEAST 8 DOMAINS HOSTING THE INSTALLER DLL: - wu4i4g[.]com - 45.10.110[.]21 - x0hohx6[.]com - 78.40.219[.]55 - xpe1qhe[.]com - 95.181.198[.]24 -- zloojq[.].com - 95.181.198[.]245 +- zloojq[.]com - 95.181.198[.]245 GET REQUESTS FOR THE INSTALLER DLL: @@ -102,4 +102,4 @@ HTTPS TRAFFIC TO LEGITIMATE DOMAINS CAUSED BY INSTALLER DLL: - port 443 - support.apple.com - port 443 - www.intel.com - port 443 - help.twitter.com -- port 443 - support.microsoft.com \ No newline at end of file +- port 443 - support.microsoft.com