EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Unwrapping Ursnifs Gifts - The DFIR Report

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 55/100

MISP EudorIA ha pubblicato l'advisory "Unwrapping Ursnifs Gifts - The DFIR Report". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Why it matters

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

AudienceITSOCCISO

Text acquired from the source

Evento MISP pubblicato con TLP:CLEAR: Unwrapping Ursnifs Gifts - The DFIR Report. Report from raw HTML https:// Skip to content In late @[tag](misp-galaxy:tool="August") 2022, we investigated an incident involving @[tag](misp-galaxy:banker="Gozi") malware, which resulted in @[tag](misp-galaxy:malpedia="Cobalt Strike") being deployed. This was followed by the threat actors moving laterally throughout the environment using an admin account. The @[tag](misp-galaxy:banker="Gozi") malware family (also commonly referred to as @[tag](misp-galaxy:banker="Gozi") or ISFB) is one of the oldest banking trojans still active today. It has an extensive past of code forks and evolutions that has lead to several active variants in the last 5 years including Dreambot, IAP, RM2, RM3 and most recently, LDR4. For this report, we have referred to the malware as @[tag](misp-galaxy:banker="Gozi") for simplicity, however we also recommend reading Mandiant’s article on LDR4. ## Case Summary In this intrusion, a malicious ISO file was delivered to a user which contained @[tag](misp-galaxy:banker="Gozi") malware. The malware displayed an interesting execution flow, which included using a renamed copy of rundll32. Once executed, the malware conducted automatic discovery on the beachhead host, as we have observed with other loaders such as IcedID. The malware also established persistence on the host with the creation of a registry run key. Approximately 4 days after the initial infection

Source
MISP EudorIA
Publishing entity
MISP EudorIA
Entity type
Intelligence community
Area
Global
Original language
it · translation not needed
Publication
30/07/2026 02:48
Sharing
TLP:CLEAR
Indicators reported by the source
134
IOCs indexed for lookup
0 values within the retention period
IOCs available in the STIX feed
119Last sharing verification: 2026-09-25T19:32:49.164387+00:00
MISP event
4bcf0465-4b53-4de4-8c53-fcc5f7d04dfc
MITRE ATT&CK
DNS - T1071.004, PowerShell - T1059.001, JavaScript - T1059.007, VNC - T1021.005, Software - T1592.002, WHOIS - T1596.002, Tool - T1588.002, Asynchronous Procedure Call - T1055.004, BITS Jobs - T1197, Compile After Delivery - T1027.004, Credentials from Password Stores - T1555, Domain Account - T1087.002, Domain Trust Discovery - T1482, Exfiltration Over C2 Channel - T1041, LSASS Memory - T1003.001, Lateral Tool Transfer - T1570, Malicious File - T1204.002, Mark-of-the-Web Bypass - T1553.005, Mshta - T1218.005, Process Discovery - T1057
Classification
Medium
Open the original source