EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Avviso tecnico

Unwrapping Ursnifs Gifts - The DFIR Report

Fonte aperta verificata
Intelligence con provenienza tracciabile. EudorIA conserva gli indicatori tecnici acquisiti dai feed supportati, con fonte, data e contesto. Gli IOC condivisibili sono disponibili nei feed STIX; le azioni di rilevamento e blocco richiedono la valutazione di validita, confidenza e applicabilita al perimetro del cliente. Consulta i feed STIX
Sintesi operativa EudorIA

Cosa significa

Priorità 55/100

MISP EudorIA ha pubblicato l'advisory "Unwrapping Ursnifs Gifts - The DFIR Report". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Perché conta

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

DestinatariITSOCCISO

Testo acquisito dalla fonte

Evento MISP pubblicato con TLP:CLEAR: Unwrapping Ursnifs Gifts - The DFIR Report. Report from raw HTML https:// Skip to content In late @[tag](misp-galaxy:tool="August") 2022, we investigated an incident involving @[tag](misp-galaxy:banker="Gozi") malware, which resulted in @[tag](misp-galaxy:malpedia="Cobalt Strike") being deployed. This was followed by the threat actors moving laterally throughout the environment using an admin account. The @[tag](misp-galaxy:banker="Gozi") malware family (also commonly referred to as @[tag](misp-galaxy:banker="Gozi") or ISFB) is one of the oldest banking trojans still active today. It has an extensive past of code forks and evolutions that has lead to several active variants in the last 5 years including Dreambot, IAP, RM2, RM3 and most recently, LDR4. For this report, we have referred to the malware as @[tag](misp-galaxy:banker="Gozi") for simplicity, however we also recommend reading Mandiant’s article on LDR4. ## Case Summary In this intrusion, a malicious ISO file was delivered to a user which contained @[tag](misp-galaxy:banker="Gozi") malware. The malware displayed an interesting execution flow, which included using a renamed copy of rundll32. Once executed, the malware conducted automatic discovery on the beachhead host, as we have observed with other loaders such as IcedID. The malware also established persistence on the host with the creation of a registry run key. Approximately 4 days after the initial infection

Fonte
MISP EudorIA
Entità pubblicatrice
MISP EudorIA
Tipo entità
Comunità di intelligence
Area
Global
Lingua originale
it · traduzione non necessaria
Pubblicazione
30/07/2026 02:48
Condivisione
TLP:CLEAR
Indicatori dichiarati dalla fonte
134
IOC indicizzati per la ricerca
0 valori nel periodo di conservazione
IOC disponibili nel feed STIX
119Ultima verifica di condivisione: 2026-09-26T13:32:06.463307+00:00
Evento MISP
4bcf0465-4b53-4de4-8c53-fcc5f7d04dfc
MITRE ATT&CK
DNS - T1071.004, PowerShell - T1059.001, JavaScript - T1059.007, VNC - T1021.005, Software - T1592.002, WHOIS - T1596.002, Tool - T1588.002, Asynchronous Procedure Call - T1055.004, BITS Jobs - T1197, Compile After Delivery - T1027.004, Credentials from Password Stores - T1555, Domain Account - T1087.002, Domain Trust Discovery - T1482, Exfiltration Over C2 Channel - T1041, LSASS Memory - T1003.001, Lateral Tool Transfer - T1570, Malicious File - T1204.002, Mark-of-the-Web Bypass - T1553.005, Mshta - T1218.005, Process Discovery - T1057
Classificazione
Media
Apri la fonte originale