Summary: 2025/04/29 04:29
First reported date: 2014/07/14
Inquiry period : 2025/04/22 04:29 ~ 2025/04/29 04:29 (7 days), 1 search results
전 기간대비 동일한 트렌드를 보이고 있습니다.
기타 Malware Operation Arctic Wolf Schiappa 등 신규 키워드도 확인됩니다.
2006 Gozi v1.0, Gozi CRM, CRM, Papras
2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*)
In September 2010, the source code of a particular Gozi CRM dll version was leaked. This led to two main branches: one became known as Gozi Prinimalka, which was merge with Pony and became Vawtrak/Neverquest.
The other branch became known as Gozi ISFB, or ISFB in short. Webinject functionality was added to this version.
There is one panel which often was used in combination with ISFB: IAP. The panel's login page comes with the title 'Login - IAP'. The body contains 'AUTHORIZATION', 'Name:', 'Password:' and a single button 'Sign in' in a minimal design. Often, the panel is directly accessible by entering the C2 IP address in a browser. But there are ISFB versions which are not directly using IAP. The bot accesses a gate, which is called the 'Dreambot' gate. See win.dreambot for further information.
ISFB often was protected by Rovnix. This led to a further complication in the naming scheme - many companies started to call ISFB Rovnix. Because the signatures started to look for Rovnix, other trojans protected by Rovnix (in particular ReactorBot and Rerdom) sometimes got wrongly labelled.
In April 2016 a combination of Gozi ISFB and Nymaim was detected. This breed became known as GozNym. The merge uses a shellcode-like version of Gozi ISFB, that needs Nymaim to run. The C2 communication is performed by Nymaim.
See win.gozi for additional historical information. Ref.
* 최근 뉴스기사 Top3:
ㆍ 2025/04/28 Arctic Wolf Promotes Dan Schiappa to President, Technology and Services
Trend graph by period
Special keyword group
Top 5
Malware Type
This is the type of malware that is becoming an issue.
Keyword | Average | Label |
---|---|---|
ISFB |
|
1 (100%) |

Attacker & Actors
The status of the attacker or attack group being issued.
No data.

Technique
This is an attack technique that is becoming an issue.
No data.

Country & Company
This is a country or company that is an issue.
No data.
Threat info
Last 5SNS
(Total : 0)No data.
News
(Total : 1)No | Title | Date |
---|---|---|
1 | Arctic Wolf Promotes Dan Schiappa to President, Technology and Services - Malware.News | 2025.04.28 |
Additional information
No | Title | Date |
---|---|---|
1 | FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023 - Malware.News | 2025.04.29 |
2 | US intensifies Salt Typhoon crackdown with public info request - Malware.News | 2025.04.29 |
3 | Trump moves threaten US cyber defenses, says former CISA director Easterly - Malware.News | 2025.04.29 |
4 | Escalating attacks against Ivanti VPN appliances expected - Malware.News | 2025.04.29 |
5 | Critical Planet Technology switch vulnerabilities pose total takeover risk - Malware.News | 2025.04.29 |
View only the last 5 |
No | Title | Date |
---|---|---|
1 | Google gibt Gemini 2.5 Pro für alle frei – zumindest ein bisschen - IT Sicherheitsnews | 2025.03.31 |
2 | VanHelsing, new RaaS in Town - Malware.News | 2025.03.23 |
3 | VanHelsing, new RaaS in Town - Malware.News | 2025.03.23 |
4 | VanHelsing, new RaaS in Town - Malware.News | 2025.03.23 |
5 | VanHelsing, new RaaS in Town - Malware.News | 2025.03.23 |
View only the last 5 |
No | URL | CC | ASN Co | Reporter | Date |
---|---|---|---|---|---|
1 | https://qusbec.com/Financing geo Gozi ISFB ITA ursnif | GB ![]() | ... | JAMESWT_MHT | 2023.10.13 |
2 | http://www.morin-fioul.com/processo/Informazioni.zip agenziaentrate geo Gozi ISFB ITA ursnif | FR ![]() | OVH SAS | JAMESWT_MHT | 2023.10.12 |
3 | http://www.morin-fioul.com/processo/Azienda.zip agenziaentrate geo Gozi ISFB ITA ursnif | FR ![]() | OVH SAS | JAMESWT_MHT | 2023.10.12 |
4 | http://www.morin-fioul.com/processo/Documenti.zip agenziaentrate geo Gozi ISFB ITA ursnif | FR ![]() | OVH SAS | JAMESWT_MHT | 2023.10.12 |
5 | http://www.morin-fioul.com/processo/Cliente.zip agenziaentrate geo Gozi ISFB ITA ursnif | FR ![]() | OVH SAS | JAMESWT_MHT | 2023.10.12 |
View only the last 5 |