Unwrapping Ursnifs Gifts - The DFIR Report
Cosa significa
MISP EudorIA ha pubblicato l'advisory "Unwrapping Ursnifs Gifts - The DFIR Report". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Perché conta
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Azioni consigliate
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Testo acquisito dalla fonte
Evento MISP pubblicato con TLP:CLEAR: Unwrapping Ursnifs Gifts - The DFIR Report. Report from raw HTML https:// Skip to content In late @[tag](misp-galaxy:tool="August") 2022, we investigated an incident involving @[tag](misp-galaxy:banker="Gozi") malware, which resulted in @[tag](misp-galaxy:malpedia="Cobalt Strike") being deployed. This was followed by the threat actors moving laterally throughout the environment using an admin account. The @[tag](misp-galaxy:banker="Gozi") malware family (also commonly referred to as @[tag](misp-galaxy:banker="Gozi") or ISFB) is one of the oldest banking trojans still active today. It has an extensive past of code forks and evolutions that has lead to several active variants in the last 5 years including Dreambot, IAP, RM2, RM3 and most recently, LDR4. For this report, we have referred to the malware as @[tag](misp-galaxy:banker="Gozi") for simplicity, however we also recommend reading Mandiant’s article on LDR4. ## Case Summary In this intrusion, a malicious ISO file was delivered to a user which contained @[tag](misp-galaxy:banker="Gozi") malware. The malware displayed an interesting execution flow, which included using a renamed copy of rundll32. Once executed, the malware conducted automatic discovery on the beachhead host, as we have observed with other loaders such as IcedID. The malware also established persistence on the host with the creation of a registry run key. Approximately 4 days after the initial infection
- Fonte
- MISP EudorIA
- Entità pubblicatrice
- MISP EudorIA
- Tipo entità
- Comunità di intelligence
- Area
- Global
- Lingua originale
- it · traduzione non necessaria
- Pubblicazione
- 30/07/2026 02:48
- Condivisione
- TLP:CLEAR
- Indicatori dichiarati dalla fonte
- 134
- IOC indicizzati per la ricerca
- 0 valori nel periodo di conservazione
- IOC disponibili nel feed STIX
- 119Ultima verifica di condivisione: 2026-09-25T19:32:49.164387+00:00
- Evento MISP
- 4bcf0465-4b53-4de4-8c53-fcc5f7d04dfc
- MITRE ATT&CK
- DNS - T1071.004, PowerShell - T1059.001, JavaScript - T1059.007, VNC - T1021.005, Software - T1592.002, WHOIS - T1596.002, Tool - T1588.002, Asynchronous Procedure Call - T1055.004, BITS Jobs - T1197, Compile After Delivery - T1027.004, Credentials from Password Stores - T1555, Domain Account - T1087.002, Domain Trust Discovery - T1482, Exfiltration Over C2 Channel - T1041, LSASS Memory - T1003.001, Lateral Tool Transfer - T1570, Malicious File - T1204.002, Mark-of-the-Web Bypass - T1553.005, Mshta - T1218.005, Process Discovery - T1057
- Classificazione
- Media