ended3월 23일· 1 sources

Ursnif Malware — Reconstructing a 6-Stage Infection Chain from a PCAP

Ursnif 악성코드 — PCAP에서 6단계 감염 체인 재구성하기

Why it matters

This write-up reconstructs a 6-stage Ursnif/Gozi banking trojan infection chain from a PCAP capture, detailing how the malware used .avi file extensions to disguise DLL payloads and TLS-encrypted C2 beaconing. The author extracted 10 IOCs, mapped each stage to MITRE ATT&CK techniques, and developed 5 Splunk detection rules from 2,180 packets.

1
Sources
+0
24h
Growth
177d
Active
UrsnifPCAPMITRE ATT&CKSplunkC2 BeaconingIOC

Sources

Related Issues