We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
TrojanDropper:HTML/IcedID
Aliases: No associated aliases
Summary
This is a detection for HTML files that embed a version of IcedID. The HTML file is typically sent as an attachment in an email that may appeal to its recipient, to tempt them into opening it.
Read the following blogs for details:
Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts.
If the attachment has been opened and the payload launched, remove the affected machine from the network as IcedID often leads to Cobalt Strike and ransomware. Here are other steps you should take to mitigate the threat:
- Notify your administrator about the malicious email.
- Delete the email and attachment.
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.