Unwrapping Ursnifs Gifts - The DFIR Report
What it means
MISP EudorIA ha pubblicato l'advisory "Unwrapping Ursnifs Gifts - The DFIR Report". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Why it matters
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Recommended actions
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Text acquired from the source
Evento MISP pubblicato con TLP:CLEAR: Unwrapping Ursnifs Gifts - The DFIR Report. Report from raw HTML https:// Skip to content In late @[tag](misp-galaxy:tool="August") 2022, we investigated an incident involving @[tag](misp-galaxy:banker="Gozi") malware, which resulted in @[tag](misp-galaxy:malpedia="Cobalt Strike") being deployed. This was followed by the threat actors moving laterally throughout the environment using an admin account. The @[tag](misp-galaxy:banker="Gozi") malware family (also commonly referred to as @[tag](misp-galaxy:banker="Gozi") or ISFB) is one of the oldest banking trojans still active today. It has an extensive past of code forks and evolutions that has lead to several active variants in the last 5 years including Dreambot, IAP, RM2, RM3 and most recently, LDR4. For this report, we have referred to the malware as @[tag](misp-galaxy:banker="Gozi") for simplicity, however we also recommend reading Mandiant’s article on LDR4. ## Case Summary In this intrusion, a malicious ISO file was delivered to a user which contained @[tag](misp-galaxy:banker="Gozi") malware. The malware displayed an interesting execution flow, which included using a renamed copy of rundll32. Once executed, the malware conducted automatic discovery on the beachhead host, as we have observed with other loaders such as IcedID. The malware also established persistence on the host with the creation of a registry run key. Approximately 4 days after the initial infection
- Source
- MISP EudorIA
- Publishing entity
- MISP EudorIA
- Entity type
- Intelligence community
- Area
- Global
- Original language
- it · translation not needed
- Publication
- 30/07/2026 02:48
- Sharing
- TLP:CLEAR
- Indicators reported by the source
- 134
- IOCs indexed for lookup
- 0 values within the retention period
- IOCs available in the STIX feed
- 119Last sharing verification: 2026-09-25T19:32:49.164387+00:00
- MISP event
- 4bcf0465-4b53-4de4-8c53-fcc5f7d04dfc
- MITRE ATT&CK
- DNS - T1071.004, PowerShell - T1059.001, JavaScript - T1059.007, VNC - T1021.005, Software - T1592.002, WHOIS - T1596.002, Tool - T1588.002, Asynchronous Procedure Call - T1055.004, BITS Jobs - T1197, Compile After Delivery - T1027.004, Credentials from Password Stores - T1555, Domain Account - T1087.002, Domain Trust Discovery - T1482, Exfiltration Over C2 Channel - T1041, LSASS Memory - T1003.001, Lateral Tool Transfer - T1570, Malicious File - T1204.002, Mark-of-the-Web Bypass - T1553.005, Mshta - T1218.005, Process Discovery - T1057
- Classification
- Medium