{"id":40378,"date":"2021-04-09T16:31:05","date_gmt":"2021-04-09T16:31:05","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=93314"},"modified":"2021-04-09T16:31:05","modified_gmt":"2021-04-09T16:31:05","slug":"investigating-a-unique-form-of-email-delivery-for-icedid-malware","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/","title":{"rendered":"Investigating a unique \u201cform\u201d of email delivery for IcedID malware"},"content":{"rendered":"<p>Microsoft threat analysts have been tracking activity where contact forms published on websites are abused to deliver malicious links to enterprises using emails with fake legal threats. The emails instruct recipients to click a link to review supposed evidence behind their allegations, but are instead led to the download of IcedID, an info-stealing malware. Microsoft Defender for Office 365 detects and blocks these emails and protects organizations from this threat.<\/p>\n<p>In this blog, we showcase our analysis on this unique attack and how the techniques behind it help attackers with their malicious goals of finding new ways to infect systems. This threat is notable because:<\/p>\n<ol>\n<li>Attackers are abusing legitimate infrastructure, such as websites\u2019 contact forms, to bypass protections, making this threat highly evasive. In addition, attackers use legitimate URLs, in this case Google URLs that require targets to sign in with their Google credentials.<\/li>\n<li>The emails are being used to deliver the IcedID malware, which can be used for reconnaissance and data exfiltration, and can lead to additional malware payloads, including ransomware.<\/li>\n<li>This threat shows attackers are always on the hunt for attack paths for infiltrating networks, and they often target services exposed to the internet. Organizations must ensure they have protections against such threats.<\/li>\n<\/ol>\n<p>While this specific campaign delivers the IcedID malware, the delivery method can be used to distribute a wide range of other malware, which can in turn introduce other threats to the enterprise. IcedID itself is a banking trojan that has evolved to become an entry point for more sophisticated threats, including human-operated ransomware. It connects to a command-and-control server and downloads additional implants and tools that allow attackers to perform hands-on-keyboard attacks, steal credentials, and move laterally across affected networks to delivering additional payloads.<\/p>\n<p>We continue to actively investigate this threat and work with partners to ensure that customers are protected. We have already alerted security groups at Google to bring attention to this threat as it takes advantage of Google URLs.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/security\/microsoft-365-defender\">Microsoft 365 Defender<\/a> defends organizations by using advanced technologies informed by <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/security\/office-365-defender\">Microsoft Defender for Office 365<\/a> and backed by security experts. Microsoft 365 Defender correlates signals on malicious emails, URLs, and files to deliver coordinated defense against evasive threats, their payloads, and their spread across networks.<\/p>\n<p>Microsoft Defender for Office 365 supports organizations throughout an attack\u2019s lifecycle, from prevention and detection to investigation, hunting, and remediation\u2013effectively protecting users through a coordinated defense framework.<\/p>\n<p>Websites typically contain contact form pages as a way to allow site visitors to communicate with site owners, removing the necessity to reveal their email address to potential spammers.<\/p>\n<p>However, in this campaign, we observed an influx of contact form emails targeted at enterprises by means of abusing companies\u2019 contact forms. This indicates that attackers may have used a tool that automates this process while circumventing CAPTCHA protections.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-93315\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Fig1-sample-contact-form.png\" alt width=\"432\" height=\"363\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Fig1-sample-contact-form.png 432w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Fig1-sample-contact-form-300x252.png 300w\" sizes=\"auto, (max-width: 432px) 100vw, 432px\"><\/p>\n<p><em>Figure 1. Sample contact form that attackers take advantage of by filling in malicious content, which gets delivered to the target enterprises<\/em><\/p>\n<p>In this campaign, we tracked that the malicious email that arrives in the recipient\u2019s inbox from the contact form query appears trustworthy as it was sent from trusted email marketing systems, further confirming its legitimacy while evading detection. As the emails are originating from the recipient\u2019s own contact form on their website, the email templates match what they would expect from an actual customer interaction or inquiry.<\/p>\n<p>As attackers fill out and submit the web-based form, an email message is generated to the associated contact form recipient or targeted enterprise, containing the attacker-generated message. The message uses strong and urgent language (\u201cDownload it right now and check this out for yourself\u201d), and pressures the recipient to act immediately, ultimately compelling recipients to click the links to avoid supposed legal action.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-93320\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Figure-2_contactform_new.png\" alt width=\"625\" height=\"795\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Figure-2_contactform_new.png 625w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Figure-2_contactform_new-236x300.png 236w\" sizes=\"auto, (max-width: 625px) 100vw, 625px\"><\/p>\n<p><em>Figure 2. A sample email delivered via contact forms that contain malicious content added by attackers<\/em><\/p>\n<p>Along with the fake legal threats written in the comments, the message content also includes a link to a <em>sites.google.com<\/em> page to view the alleged stolen photos for the recipient to view.<\/p>\n<p>Clicking the link brings the recipient to a Google page that requires them to sign in with their Google credentials. Because of this added authentication layer, detection technologies may fail in identifying the email as malicious altogether.<\/p>\n<p>After the email recipient signs in, the <em>sites.google.com<\/em> page automatically downloads a malicious ZIP file, which contains a heavily obfuscated .js file. The malicious .js file is executed via WScript to create a shell object for launching PowerShell to download the IcedID payload (a .dat file), which is decrypted by a dropped DLL loader, as well as a Cobalt Strike beacon in the form of a stageless DLL, allowing attackers to remotely control the compromised device.<\/p>\n<p>The downloaded .dat file loads via the rundll32 executable. The rundll32 executable then launches numerous commands related to the following info-stealing capabilities:<\/p>\n<ul>\n<li>Machine discovery<\/li>\n<li>Obtaining machine AV info<\/li>\n<li>Getting IP and system information<\/li>\n<li>Domain information<\/li>\n<li>Dropping SQLite for accessing credentials stored in browser databases<\/li>\n<\/ul>\n<p>The diagram in Figure 3 provides a broad illustration of how attackers carry out these malicious email campaigns, starting from identifying their targets\u2019 contact forms and ending with the IcedID malware payload.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-93317\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Fig3-attack-chain.png\" alt width=\"936\" height=\"323\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Fig3-attack-chain.png 936w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Fig3-attack-chain-300x104.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Fig3-attack-chain-768x265.png 768w\" sizes=\"auto, (max-width: 936px) 100vw, 936px\"><\/p>\n<p><em>Figure 3. Contact form attack chain results in the IcedID payload<\/em><\/p>\n<p>We noted a primary and secondary attack chain under the execution and persistence stages. The primary attack chain follows an attack flow from downloading malicious .zip file from the <em>sites.google.com<\/em> link, all the way to the IcedID payload. The secondary attack chain, on the other hand, appears to be a backup attack flow for when the <em>sites.google.com<\/em> page in the primary attack chain has already been taken down.<\/p>\n<p>In the secondary chain, users are redirected to a .top domain, while inadvertently accessing a Google User Content page, which downloads the malicious .ZIP file. Further analysis reveals that the forms contain malicious <em>sites.google.com<\/em> links that download the IcedID malware.<\/p>\n<p>When run, IcedID connects to a command-and-control server to download modules that run its primary function of capturing and exfiltrating banking credentials and other information. It achieves persistence via schedule tasks. It also downloads implants like Cobalt Strike and other tools, which allow remote attackers to run malicious activities on the compromised system, including collecting additional credentials, moving laterally, and delivering secondary payloads.<\/p>\n<p>This campaign is not only successful because it takes advantage of legitimate contact form emails, but the message content also passes as something that recipients would expect to receive. This creates a high risk of attackers successfully delivering email to inboxes, thereby allowing for \u201csafe\u201d emails that would otherwise be filtered out into spam folders.<\/p>\n<p>In the samples we found, attackers used legal threats as a scare tactic while claiming that the recipients allegedly used their images or illustrations without their consent, and that legal action will be taken against them. There is also a heightened sense of urgency in the email wording, with phrases such as \u201cyou could be sued,\u201d and \u201cit\u2019s not legal.\u201d It\u2019s a sly and devious approach since everything else about this email is authentic and legitimate.<\/p>\n<p>We observed more emails sent by attackers on other contact forms that contain similar wording around legal threats. The messages consistently mention a copyright claim lure by a photographer, illustrator, or designer with the same urgency to click the <em>sites.google.com<\/em> link.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-93318\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Fig4-sample-emails.png\" alt width=\"936\" height=\"334\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Fig4-sample-emails.png 936w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Fig4-sample-emails-300x107.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Fig4-sample-emails-768x274.png 768w\" sizes=\"auto, (max-width: 936px) 100vw, 936px\"><\/p>\n<p><em>Figure 4. Samples of contact form emails that use the photographer copyright lure with a sites.gooogle.com link<\/em><\/p>\n<p>In a typical contact form, users are required to input their name, email address, and a message or comment. In the samples we obtained, attackers used fake names that start with \u201cMel,\u201d such as \u201cMelanie\u201d or \u201cMeleena,\u201d and used a standard format for their fake email addresses that include a portion of their fake name + words associated photography + three numbers. Some examples include:<\/p>\n<ul>\n<li>mphotographer550@yahoo.com<\/li>\n<li>mephotographer890@hotmail.com<\/li>\n<li>mgallery487@yahoo.com<\/li>\n<li>mephoto224@hotmail.com<\/li>\n<li>megallery736@aol.com<\/li>\n<li>mshot373@yahoo.com<\/li>\n<\/ul>\n<p>As this research shows, adversaries remain motivated to find new ways to deliver malicious email to enterprises with the clear intent to evade detection. The scenarios we observed offer a serious glimpse into how sophisticated attackers\u2019 techniques have grown, while maintaining the goal of delivering dangerous malware payloads such as IcedID. Their use of submission forms is notable because the emails don\u2019t have the typical marks of malicious messages and are seemingly legitimate.<\/p>\n<p>To protect customers from this highly evasive campaign, <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/security\/office-365-defender\">Microsoft Defender for Office 365<\/a> inspects the email body and URL for known patterns. Defender for Office 365 enables this by leveraging its deep visibility into email threats and advanced detection technologies powered by AI and machine learning, backed by Microsoft experts who constantly monitor the threat landscape for new attacker tools and techniques. Expert monitoring is especially critical in detecting this campaign given the delivery method and the nature of the malicious emails.<\/p>\n<p>In addition, the protection delivered by Microsoft Defender for Office 365 is enriched by signals from other Microsoft 365 Defender services, which detect other components of this attack. For example, Microsoft Defender for Endpoint detects the IcedID payload and surfaces this intelligence across Microsoft 365 Defender. With its cross-domain optics, Microsoft 365 Defender correlates threat data on files, URLs, and emails to provide end-to-end visibility into attack chains. This allows us to trace detections of malware and malicious behavior to the delivery method, in this case, legitimate-looking emails, enabling us to build comprehensive and durable protections, even as attackers continue to tweak their campaigns to further evade detection.<\/p>\n<p>By running custom queries using advanced hunting in Microsoft 365 Defender, customers can proactively locate threats related to this attack.<\/p>\n<p>To locate emails that may be related to this activity, run the following <a href=\"https:\/\/security.microsoft.com\/hunting?query=H4sIAAAAAAAEAG2SzU4CQRCE62ziO0y4gImRs1w0MZBwkIOGG4nhZ1kW2R3DLiJR392vG9ggIRNme7pqqqt76CrXWJlWGmrN3lehuaKudaUfBW21UAKSEO8ZwW9UmjpScjY05fdF_KiGRpqQz-AYPtIdaGSl3E78POWUE7X1CS-hisUtPajDeaYbohHfb93rVr-u2Kg9Lbmd4TOoW7vvopSQq9xRdHRApkI74vBdz-6mhG9e-6ibXptlzOhuO8QvfD9QHOPSuq68z-BTWbEiilY9JVdqg7Ml-BReADVkP5WtT2BxohAdC16_8KmOveqM3EQ79h2cDXm7nZxMsemKT65QubOqrp7DKZ2573ru_eZEGXEgFw9vZPzVYUJrn43VKpxZeKUMbetxd_H9X8-6XcAu9cZecKOFy3OHQ_AmLxjYB_7OR5X_ro-c8_u9Qy9HvFf3dqn3Jv-bP2MYzmvQAgAA&amp;runQuery=true&amp;timeRangeId=month\">query:<\/a><\/p>\n<p><code>EmailUrlInfo<br \/>| where Url matches regex @\"\\bsites\\.google\\.com\\\/view\\\/(?:id)?\\d{9,}\\b\"<br \/>| join EmailEvents on NetworkMessageId<br \/>\/\/ Note: Replace the following subject lines with the one generated by your website's Contact submission form if no results return initially<br \/>| where Subject has_any('Contact Us', 'New Submission', 'Contact Form', 'Form submission')<\/code><\/p>\n<p>To find malicious downloads associated with this threat, run the following <a href=\"https:\/\/security.microsoft.com\/hunting?query=H4sIAAAAAAAEAKWS3WrCQBCFz7XgO8heKRRvfQEr9KIqgteiJprQxJSsrT-UPrvfji4UI3hRwuwyM-ec-dkMlepbudbcI-6C-5VIqp328mqrpR91dFBGrMY6eiOXk821tHOnrabkKlPxfFFpDKI0TkD9qiuH74kkcFL1sSPm9ALGwc9Mp3yQC94nqpV1UTfyA52p-96Ib6gdGBuYx0Z2ZfUO1lOtxc3_uKvQe7iHOOUEP2eeMOPMKgXEtcs5VoDN2IS3in2myDCHt4SR_ENpT6_PlSIzcheGPtlrbFGoOAPn67aFNZHw-td_IG7qLzLGEntzbxu6ADunZbJKAgAA&amp;runQuery=true&amp;timeRangeId=month\">query:<\/a><\/p>\n<p><code>DeviceFileEvents<br \/>|&nbsp;where&nbsp;InitiatingProcessFileName&nbsp;in~(\"msedge.exe\",&nbsp;\"chrome.exe\",&nbsp;\"explorer.exe\",&nbsp;\"7zFM.exe\",&nbsp;\"firefox.exe\",&nbsp;\"browser_broker.exe\")<br \/>|&nbsp;where&nbsp;FileOriginReferrerUrl&nbsp;has&nbsp;\".php\"&nbsp;and&nbsp;FileOriginReferrerUrl&nbsp;has&nbsp;\".top\"&nbsp;and&nbsp;FileOriginUrl&nbsp;&nbsp;has_any(\"googleusercontent\",&nbsp;\"google\",&nbsp;\"docs\")<\/code><\/p>\n<p>As this attack abuses legitimate services, it\u2019s also important for customers to review <a href=\"https:\/\/docs.microsoft.com\/en-us\/exchange\/security-and-compliance\/mail-flow-rules\/manage-mail-flow-rules\">mail flow rules<\/a> to check for broad exceptions, such those related to IP ranges and domain-level allow lists, that may be letting these emails through.<\/p>\n<p>We also encourage customers to continuously build organizational resilience against email threats by educating users about identifying social engineering attacks and preventing malware infection. Use <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/attack-simulation-training-get-started?view=o365-worldwide\">Attack simulation training<\/a> in Microsoft Defender for Office 365 to run attack scenarios, increase user awareness, and empower employees to recognize and report these attacks.<\/p>\n<p><strong><em>Emily Hacker with Justin Carroll<\/em><\/strong><br \/><em>Microsoft 365 Defender Threat Intelligence Team<\/em><\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/04\/09\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft threat analysts have been tracking activity where contact forms published on websites are abused to deliver malicious links to enterprises using emails with fake legal threats. The emails instruct recipients to click a link to review supposed evidence behind their allegations, but are instead led to the download of IcedID, an info-stealing malware.<br \/>\nThe post Investigating a unique &#8220;form&#8221; of email delivery for IcedID malware appeared first on Microsoft Security. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":40379,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[9321,347,927,7221],"class_list":["post-40378","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-contact-form","tag-cybersecurity","tag-icedid","tag-microsoft-security-intelligence"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Investigating a unique \u201cform\u201d of email delivery for IcedID malware 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Investigating a unique \u201cform\u201d of email delivery for IcedID malware 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-04-09T16:31:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/investigating-a-unique-form-of-email-delivery-for-icedid-malware.png\" \/>\n\t<meta property=\"og:image:width\" content=\"432\" \/>\n\t<meta property=\"og:image:height\" content=\"363\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Investigating a unique \u201cform\u201d of email delivery for IcedID malware\",\"datePublished\":\"2021-04-09T16:31:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/\"},\"wordCount\":1733,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware.png\",\"keywords\":[\"contact form\",\"Cybersecurity\",\"IcedID\",\"Microsoft security intelligence\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/\",\"name\":\"Investigating a unique \u201cform\u201d of email delivery for IcedID malware 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware.png\",\"datePublished\":\"2021-04-09T16:31:05+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware.png\",\"width\":432,\"height\":363},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"contact form\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/contact-form\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Investigating a unique \u201cform\u201d of email delivery for IcedID malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Investigating a unique \u201cform\u201d of email delivery for IcedID malware 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/","og_locale":"en_US","og_type":"article","og_title":"Investigating a unique \u201cform\u201d of email delivery for IcedID malware 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-04-09T16:31:05+00:00","og_image":[{"width":432,"height":363,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/investigating-a-unique-form-of-email-delivery-for-icedid-malware.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Investigating a unique \u201cform\u201d of email delivery for IcedID malware","datePublished":"2021-04-09T16:31:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/"},"wordCount":1733,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/investigating-a-unique-form-of-email-delivery-for-icedid-malware.png","keywords":["contact form","Cybersecurity","IcedID","Microsoft security intelligence"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/","url":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/","name":"Investigating a unique \u201cform\u201d of email delivery for IcedID malware 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/investigating-a-unique-form-of-email-delivery-for-icedid-malware.png","datePublished":"2021-04-09T16:31:05+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/investigating-a-unique-form-of-email-delivery-for-icedid-malware.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/investigating-a-unique-form-of-email-delivery-for-icedid-malware.png","width":432,"height":363},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/investigating-a-unique-form-of-email-delivery-for-icedid-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"contact form","item":"https:\/\/www.threatshub.org\/blog\/tag\/contact-form\/"},{"@type":"ListItem","position":3,"name":"Investigating a unique \u201cform\u201d of email delivery for IcedID malware"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40378","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=40378"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40378\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/40379"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=40378"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=40378"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=40378"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}