A new malspam campaign was found distributing IcedID earlier this week. The malspam pushes different Word docs from the same links, which contain IcedID, executed when a user enables content or macros for these files. Below is the infection flow for IcedID.
Below are two different samples of word documents analyzed by security researchers. The first Word document had a template that was mostly red (maybe reddish-orange). My second sample had a different template that was mostly blue.
As opposed to earlier samples of IcedID, this particular infection contained no Trickbot. Infected Windows hosts showed the same type of artifacts and behavior associated with IcedID in recent months.