Inhalt nur in Originalsprache verfügbar
class="post-article">

Gozi

Gozi ISFB Ursnif banking trojan. RegSaveKeyA registry dump. NotifyBootConfigStatus boot persistence.

Bedrohungsprofil
Typ Botnet
ProgrammierspracheC++
C2-ProtokollHTTP (RC4)
Erstmals gesehen2007
Ziele Avrupa/Kuresel Finansal
Zweck / Fähigkeiten
  • Banking Fraud/Form Grab
Für diese Familie wurden noch keine C2-Server identifiziert.

Forschungsberichte (3)

Yüksek

Gozi2 -- atw3.dll Kısa DLL, RegSaveKeyA Registry Dökümü, NotifyBootConfigStatus Önyükleme Kalıcılığı | Yüksek

Gozi2 468KB atw3.dll kisa DLL. RegSaveKeyA kayit defteri dosya döküm. NotifyBootConfigStatus Windows boot config API. SHEnumKeyExA kabuk anahtari sayimi.

Bericht lesen →
Kritik

Gozi/Ursnif -- 467KB DLL, atw3.dll, 776 String Yoğun Paketleme, C2 Config | Kritik

Gozi Ursnif 467KB DLL (atw3.dll). 776 string yoğun paketleme. 252C2U2e2r2 C2 config.

Bericht lesen →
Yüksek

Gozi/ISFB Banking Trojan — atw3.dll Sifrelenmis DLL, 776 String, Yuksek Paketleme | Yuksek

Gozi/ISFB banking trojan atw3.dll. 776 string, yuksek paketleme seviyesi. Web inject, keylog, form grab yetenekleri.

Bericht lesen →