Summary: 2025/04/29 00:06

First reported date: 2014/07/14
Inquiry period : 2025/04/28 00:06 ~ 2025/04/29 00:06 (1 days), 1 search results

지난 7일 기간대비 신규 트렌드를 보이고 있습니다.
악성코드 유형
ISFB 도 새롭게 확인됩니다.
기타 Malware Operation Arctic Wolf Schiappa 등 신규 키워드도 확인됩니다.

2006 Gozi v1.0, Gozi CRM, CRM, Papras
2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*)

In September 2010, the source code of a particular Gozi CRM dll version was leaked. This led to two main branches: one became known as Gozi Prinimalka, which was merge with Pony and became Vawtrak/Neverquest.

The other branch became known as Gozi ISFB, or ISFB in short. Webinject functionality was added to this version.

There is one panel which often was used in combination with ISFB: IAP. The panel's login page comes with the title 'Login - IAP'. The body contains 'AUTHORIZATION', 'Name:', 'Password:' and a single button 'Sign in' in a minimal design. Often, the panel is directly accessible by entering the C2 IP address in a browser. But there are ISFB versions which are not directly using IAP. The bot accesses a gate, which is called the 'Dreambot' gate. See win.dreambot for further information.

ISFB often was protected by Rovnix. This led to a further complication in the naming scheme - many companies started to call ISFB Rovnix. Because the signatures started to look for Rovnix, other trojans protected by Rovnix (in particular ReactorBot and Rerdom) sometimes got wrongly labelled.

In April 2016 a combination of Gozi ISFB and Nymaim was detected. This breed became known as GozNym. The merge uses a shellcode-like version of Gozi ISFB, that needs Nymaim to run. The C2 communication is performed by Nymaim.

See win.gozi for additional historical information.  Ref.

 * 최근 뉴스기사 Top3:
    ㆍ 2025/04/28 Arctic Wolf Promotes Dan Schiappa to President, Technology and Services

Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1Malware 1 ▲ new
2ISFB 1 ▲ new
3Operation 1 ▲ new
4Arctic 1 ▲ new
5Wolf 1 ▲ new
6Schiappa 1 ▲ new
7Dan 1 ▲ new
8President 1 ▲ new
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


Keyword Average Label
ISFB
1 (100%)
Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


No data.

Attack technique
Technique

This is an attack technique that is becoming an issue.


No data.

Country & Company
Country & Company

This is a country or company that is an issue.


No data.

Threat info
Last 5

SNS

(Total : 0)

No data.

News

(Total : 1)
  Total keyword

Malware ISFB Operation

No Title Date
1Arctic Wolf Promotes Dan Schiappa to President, Technology and Services - Malware.News2025.04.28

Additional information

No Title Date
1Google gibt Gemini 2.5 Pro für alle frei – zumindest ein bisschen - IT Sicherheitsnews2025.03.31
2VanHelsing, new RaaS in Town - Malware.News2025.03.23
3VanHelsing, new RaaS in Town - Malware.News2025.03.23
4VanHelsing, new RaaS in Town - Malware.News2025.03.23
5VanHelsing, new RaaS in Town - Malware.News2025.03.23
View only the last 5
No data
No data
No data
No URL CC ASN Co Reporter Date
1https://qusbec.com/Financing
geo Gozi ISFB ITA ursnif
GB GB...JAMESWT_MHT2023.10.13
2http://www.morin-fioul.com/processo/Informazioni.zip
agenziaentrate geo Gozi ISFB ITA ursnif
FR FROVH SASJAMESWT_MHT2023.10.12
3http://www.morin-fioul.com/processo/Azienda.zip
agenziaentrate geo Gozi ISFB ITA ursnif
FR FROVH SASJAMESWT_MHT2023.10.12
4http://www.morin-fioul.com/processo/Documenti.zip
agenziaentrate geo Gozi ISFB ITA ursnif
FR FROVH SASJAMESWT_MHT2023.10.12
5http://www.morin-fioul.com/processo/Cliente.zip
agenziaentrate geo Gozi ISFB ITA ursnif
FR FROVH SASJAMESWT_MHT2023.10.12
View only the last 5
Beta Service, If you select keyword, you can check detailed information.