Malware
ISFB
aka Gozi ISFB · IAP · Pandemyia
2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) In September 2010, the source code of a particular Gozi CRM dll version was leaked.
ISFB, also known as Gozi ISFB, IAP, Pandemyia, is a Windows malware family operated by GOLD CABIN.
Background
The lineage spans 2006 (Gozi v1.0, Gozi CRM, CRM, Papras) and 2010 (Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*)). In September 2010 the source code of a specific Gozi CRM dll version was leaked, which spawned two principal branches. One became Gozi Prinimalka, later merged with Pony to form Vawtrak/Neverquest.
The second branch came to be called Gozi ISFB, or simply ISFB, and webinject functionality was introduced into this version.
A panel frequently paired with ISFB is IAP. Its login page carries the title 'Login - IAP', and the body presents 'AUTHORIZATION', 'Name:', 'Password:', and a lone 'Sign in' button in a sparse layout. The panel can often be reached directly by typing the C2 IP address into a browser, though some ISFB builds do not use IAP directly; instead the bot connects to a gate known as the 'Dreambot' gate (see win.dreambot for more).
ISFB was commonly wrapped in Rovnix, which muddied naming since many vendors began labeling ISFB as Rovnix. Because signatures targeted Rovnix, other Rovnix-protected trojans, notably ReactorBot and Rerdom, were at times misidentified.
In April 2016, a fusion of Gozi ISFB and Nymaim surfaced and was named GozNym. This hybrid relies on a shellcode-style build of Gozi ISFB that requires Nymaim to execute, with Nymaim handling the C2 communication.
See win.gozi for further historical background.
Source: Malpedia (Fraunhofer FKIE).