Manuel Statik Analiz — Ursnif/Gozi | Tehdit: YUKSEK

Dosya Kimliği

SHA25623df2b11dc7a52f61841921b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2
Dosya Adımagic.js (obfuskasyon imgesi)
Boyut1.841.921 byte (1.8MB JS)
String Sayisi1 (BİR!) — 1.8MB kod, sıfıra yakın okunabilir string

Meşru Domain Kamuflajı

Yenilikçi Teknik: Gerçek meşru domainler kod içine gömülüyor → statik analiz "zararsız" görür!
kpmg.com        -- KPMG Big4 muhasebe firması
thelancet.com   -- The Lancet tıp dergisi
-- Bu domainler gerçek C2 değil, kamuflaj!
-- Statik analiz: "meşru domain var → zararsız"
-- Gerçek C2: Base64/eval zinciri derininde gizli
-- Discord CDN: cdn.discordapp.com payload delivery

IOC

SHA25623df2b11dc7a52f61841921b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2
Deliverycdn.discordapp.com (Discord CDN)
Teknik1 string / 1.8MB (maksimum obfuskie)

Ursnif — Malware Profile

Ursnif/Gozi ISFB banking trojan 2007. magic.js 1 string max obfuski. kpmg/thelancet camouflage. Discord CDN. Man-in-browser.

Malware Type
Other
Programming Language
C++
C2 Protocol
HTTPS
Target Systems
Windows
Also Known As (AKA)
Gozi

Technical Details

Ursnif (Gozi/ISFB) is one of the oldest banking trojans, active since 2007. Source code leaked 2010 and 2015 spawning numerous variants: ISFB, RM3, LDR4. Man-in-the-browser attacks: form grabbing, video capture of banking sessions, web injections. C2 uses RSA-1024 encrypted HTTPS with domain generation algorithm (DGA) as fallback. RSA-2048 for config encryption, custom binary protocol. Anti-analysis: timing-based sandbox evasion, VMware/VirtualBox artifact detection. LDR4 variant (2022) dropped banking features to focus purely on ransomware delivery. Operated by TA544 (Narwhal Spider) in Italy, and by TA551 (Shathak) in Japan. Uses HTTPS for exfiltration with binary data format.

Attribution / Threat Actor

TA544 (Narwhal Spider), TA551 (Shathak), multiple operators

Capabilities & Behavior

Zararlı Yazılım Aktivitesi
Kalıcılık Mekanizması
C2 İletişimi
Anti-Analiz

IOC List (3 indicators)

IOC — Ursnif
# DOMAIN kpmg.com # DOMAIN thelancet.com # DOMAIN discordapp.com
TypeValueNote
domain kpmg.com
domain thelancet.com
domain discordapp.com

C2 Servers (1 recorded servers for this family)

Address Type Port Protocol Status Country
91.92.109.38 ip 8080 HTTP sinkholed RU

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
ursnifgozimagic-js1-stringkpmg-camouflagethelancet-camouflagediscord-cdnmax-obfuscation