We see you, Gozi
ID: ef716abc-8598-5dc0-ae08-a5a640f78d5c
STIX ID: report--ef716abc-8598-5dc0-ae08-a5a640f78d5c
Feed Name: Group-IB Blog
This report analyzes a June 2022 sample of the ISFB/Gozi banking Trojan, detailing a multi-stage in-memory kill chain where an initial self-extracting EXE launches a .NET downloader, which fetches an obfuscated .NET packer from a Discord CDN via a URL shortener; the packer decrypts and unpacks a Gozi downloader DLL that attempts to contact C2 servers to retrieve the main module. The write-up includes a high-level breakdown of each stage, the Gozi downloader configuration, and IOCs (file hashes, filenames, and network URLs) observed during the investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
