Summary: 2025/04/29 00:06
First reported date: 2014/07/14
Inquiry period : 2025/04/28 00:06 ~ 2025/04/29 00:06 (1 days), 1 search results
지난 7일 기간대비 신규 트렌드를 보이고 있습니다.
악성코드 유형 ISFB 도 새롭게 확인됩니다.
기타 Malware Operation Arctic Wolf Schiappa 등 신규 키워드도 확인됩니다.
2006 Gozi v1.0, Gozi CRM, CRM, Papras
2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*)
In September 2010, the source code of a particular Gozi CRM dll version was leaked. This led to two main branches: one became known as Gozi Prinimalka, which was merge with Pony and became Vawtrak/Neverquest.
The other branch became known as Gozi ISFB, or ISFB in short. Webinject functionality was added to this version.
There is one panel which often was used in combination with ISFB: IAP. The panel's login page comes with the title 'Login - IAP'. The body contains 'AUTHORIZATION', 'Name:', 'Password:' and a single button 'Sign in' in a minimal design. Often, the panel is directly accessible by entering the C2 IP address in a browser. But there are ISFB versions which are not directly using IAP. The bot accesses a gate, which is called the 'Dreambot' gate. See win.dreambot for further information.
ISFB often was protected by Rovnix. This led to a further complication in the naming scheme - many companies started to call ISFB Rovnix. Because the signatures started to look for Rovnix, other trojans protected by Rovnix (in particular ReactorBot and Rerdom) sometimes got wrongly labelled.
In April 2016 a combination of Gozi ISFB and Nymaim was detected. This breed became known as GozNym. The merge uses a shellcode-like version of Gozi ISFB, that needs Nymaim to run. The C2 communication is performed by Nymaim.
See win.gozi for additional historical information. Ref.
* 최근 뉴스기사 Top3:
ㆍ 2025/04/28 Arctic Wolf Promotes Dan Schiappa to President, Technology and Services
Trend graph by period
Special keyword group
Top 5
Malware Type
This is the type of malware that is becoming an issue.
Keyword | Average | Label |
---|---|---|
ISFB |
|
1 (100%) |

Attacker & Actors
The status of the attacker or attack group being issued.
No data.

Technique
This is an attack technique that is becoming an issue.
No data.

Country & Company
This is a country or company that is an issue.
No data.
Threat info
Last 5SNS
(Total : 0)No data.
News
(Total : 1)No | Title | Date |
---|---|---|
1 | Arctic Wolf Promotes Dan Schiappa to President, Technology and Services - Malware.News | 2025.04.28 |
Additional information
No | Title | Date |
---|---|---|
1 | Employee monitoring app exposes users, leaks 21+ million screenshots - Malware.News | 2025.04.28 |
2 | Introducing XSIAM 3.0 - Malware.News | 2025.04.28 |
3 | Deploy Bravely with Prisma AIRS - Malware.News | 2025.04.28 |
4 | 2025 Cyber Resilience Research Discovers Speed of AI Advancing Emerging Attack Types - Malware.News | 2025.04.28 |
5 | Intel CEO Targets Change in Corporate Culture to Shape Up - Bloomberg Technology | 2025.04.28 |
View only the last 5 |
No | Title | Date |
---|---|---|
1 | Google gibt Gemini 2.5 Pro für alle frei – zumindest ein bisschen - IT Sicherheitsnews | 2025.03.31 |
2 | VanHelsing, new RaaS in Town - Malware.News | 2025.03.23 |
3 | VanHelsing, new RaaS in Town - Malware.News | 2025.03.23 |
4 | VanHelsing, new RaaS in Town - Malware.News | 2025.03.23 |
5 | VanHelsing, new RaaS in Town - Malware.News | 2025.03.23 |
View only the last 5 |
No | URL | CC | ASN Co | Reporter | Date |
---|---|---|---|---|---|
1 | https://qusbec.com/Financing geo Gozi ISFB ITA ursnif | GB ![]() | ... | JAMESWT_MHT | 2023.10.13 |
2 | http://www.morin-fioul.com/processo/Informazioni.zip agenziaentrate geo Gozi ISFB ITA ursnif | FR ![]() | OVH SAS | JAMESWT_MHT | 2023.10.12 |
3 | http://www.morin-fioul.com/processo/Azienda.zip agenziaentrate geo Gozi ISFB ITA ursnif | FR ![]() | OVH SAS | JAMESWT_MHT | 2023.10.12 |
4 | http://www.morin-fioul.com/processo/Documenti.zip agenziaentrate geo Gozi ISFB ITA ursnif | FR ![]() | OVH SAS | JAMESWT_MHT | 2023.10.12 |
5 | http://www.morin-fioul.com/processo/Cliente.zip agenziaentrate geo Gozi ISFB ITA ursnif | FR ![]() | OVH SAS | JAMESWT_MHT | 2023.10.12 |
View only the last 5 |