Ankit Anubhav on Twitter: "#IcedID is abusing good old CHM help files. Stolen chain leads to password protected zip which has an ISO. ISO contains CHM + malicious DLL. Victim clicks on CHM and the magic starts ! Good scope of adding some parent process rules. C2 /abegelkunic.com https://t.co/0QqqFVWHxH https://t.co/KHQ3QW14Cv" / Twitter
https://twitter.com/ankit_anubhav/status/1557031483755245568