Summary: 2025/04/29 04:39

First reported date: 2014/07/14
Inquiry period : 2025/03/30 04:39 ~ 2025/04/29 04:39 (1 months), 7 search results

전 기간대비 71% 높은 트렌드를 보이고 있습니다.
전 기간대비 상승한 Top5 연관 키워드는
ISFB 입니다.
공격기술 DDoS 도 새롭게 확인됩니다.
기관 및 기업 Google United States China 도 새롭게 확인됩니다.
기타 Register ExMeta exec Senate Zucks 등 신규 키워드도 확인됩니다.

2006 Gozi v1.0, Gozi CRM, CRM, Papras
2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*)

In September 2010, the source code of a particular Gozi CRM dll version was leaked. This led to two main branches: one became known as Gozi Prinimalka, which was merge with Pony and became Vawtrak/Neverquest.

The other branch became known as Gozi ISFB, or ISFB in short. Webinject functionality was added to this version.

There is one panel which often was used in combination with ISFB: IAP. The panel's login page comes with the title 'Login - IAP'. The body contains 'AUTHORIZATION', 'Name:', 'Password:' and a single button 'Sign in' in a minimal design. Often, the panel is directly accessible by entering the C2 IP address in a browser. But there are ISFB versions which are not directly using IAP. The bot accesses a gate, which is called the 'Dreambot' gate. See win.dreambot for further information.

ISFB often was protected by Rovnix. This led to a further complication in the naming scheme - many companies started to call ISFB Rovnix. Because the signatures started to look for Rovnix, other trojans protected by Rovnix (in particular ReactorBot and Rerdom) sometimes got wrongly labelled.

In April 2016 a combination of Gozi ISFB and Nymaim was detected. This breed became known as GozNym. The merge uses a shellcode-like version of Gozi ISFB, that needs Nymaim to run. The C2 communication is performed by Nymaim.

See win.gozi for additional historical information.  Ref.

 * 최근 뉴스기사 Top3:
    ㆍ 2025/03/31 Google gibt Gemini 2.5 Pro für alle frei – zumindest ein bisschen

Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1ISFB 7 ▲ 5 (71%)
2Google 2 ▲ new
3Register 1 ▲ new
4ExMeta 1 ▲ new
5exec 1 ▲ new
6Senate 1 ▲ new
7Zucks 1 ▲ new
8United States 1 ▲ new
9China 1 ▲ new
10Yes 1 ▲ new
11mean 1 ▲ new
12following 1 ▲ new
13time 1 ▲ new
14Im 1 ▲ new
15Malware 1 - 0 (0%)
16Operation 1 ▲ new
17Arctic 1 ▲ new
18Wolf 1 ▲ new
19Schiappa 1 ▲ new
20Dan 1 ▲ new
21acquisition 1 ▲ new
22Googles 1 ▲ new
23part 1 ▲ new
24Alert 1 ▲ new
25Software 1 ▲ new
26Gemini 1 ▲ new
27Pro 1 ▲ new
28gibt 1 ▲ new
29alle 1 ▲ new
30Brussels 1 ▲ new
31DDoS 1 ▲ new
32NoName 1 ▲ new
33Wiz 1 ▲ new
34multiple 1 ▲ new
35target 1 ▲ new
36Go 1 ▲ new
37GoResolver 1 ▲ new
38analysis 1 ▲ new
39tool 1 ▲ new
40symbol 1 ▲ new
41cloud 1 ▲ new
42President 1 ▲ new
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


Keyword Average Label
ISFB
7 (100%)
Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


No data.

Attack technique
Technique

This is an attack technique that is becoming an issue.


Keyword Average Label
DDoS
1 (100%)
Country & Company
Country & Company

This is a country or company that is an issue.


Keyword Average Label
Google
2 (50%)
United States
1 (25%)
China
1 (25%)
Threat info
Last 5

Additional information

No Title Date
1Google gibt Gemini 2.5 Pro für alle frei – zumindest ein bisschen - IT Sicherheitsnews2025.03.31
2VanHelsing, new RaaS in Town - Malware.News2025.03.23
3VanHelsing, new RaaS in Town - Malware.News2025.03.23
4VanHelsing, new RaaS in Town - Malware.News2025.03.23
5VanHelsing, new RaaS in Town - Malware.News2025.03.23
View only the last 5
No data
No data
No data
No URL CC ASN Co Reporter Date
1https://qusbec.com/Financing
geo Gozi ISFB ITA ursnif
GB GB...JAMESWT_MHT2023.10.13
2http://www.morin-fioul.com/processo/Informazioni.zip
agenziaentrate geo Gozi ISFB ITA ursnif
FR FROVH SASJAMESWT_MHT2023.10.12
3http://www.morin-fioul.com/processo/Azienda.zip
agenziaentrate geo Gozi ISFB ITA ursnif
FR FROVH SASJAMESWT_MHT2023.10.12
4http://www.morin-fioul.com/processo/Documenti.zip
agenziaentrate geo Gozi ISFB ITA ursnif
FR FROVH SASJAMESWT_MHT2023.10.12
5http://www.morin-fioul.com/processo/Cliente.zip
agenziaentrate geo Gozi ISFB ITA ursnif
FR FROVH SASJAMESWT_MHT2023.10.12
View only the last 5
Beta Service, If you select keyword, you can check detailed information.