Contenu disponible en langue originale
class="post-article">

Gozi2

Gozi ISFB banking trojan VBScript dropper. ZatWDYVMlX array obfuskasyon. Double numeric VBS filename. 2006dan beri aktif Ursnif GozNym turevi.

Profil de menace
Type Backdoor
Langage de programmationVBScript
Protocole C2HTTPS
Première détection2006
Cibles Küresel/Bankacılık
Objectif / Capacités
  • Banking Trojan
Aucun serveur C2 n'a encore été identifié pour cette famille.

Rapports de recherche (1)

Orta

Gozi/ISFB -- 36599208287637_182387937827.vbs Çift Sayısal VBS, ZatWDYVMlX Array Obfuskasyon | Orta

Gozi ISFB 2MB 36599208287637_182387937827.vbs cift sayisal VBS dropper. ZatWDYVMlX=array(r5,G2,E1...) agir obfuskatyon. Tek string.

Lire le rapport →