Rewterz
Rewterz Threat Alert – FormBook Malware – Active IOCs
March 18, 2022
Rewterz
Rewterz Threat Alert – AZORult Malware – Active IOCs
March 18, 2022

Rewterz Threat Alert – GuLoader Malspam Campaign – Active IOCs

Severity

Medium

Analysis Summary

Since 2019, Guloader has been in operation as a downloader. GuLoader spreads through spam campaigns with malicious archived attachments. GuLoader downloads the bulk of malware, with the most frequent being AgentTesla, FormBook, and NanoCore. The encrypted payloads of this downloader are usually saved on Google Drive. It also acquired its payloads from Microsoft OneDrive and an attacker-controlled website.

GuLoader can avoid network-based detection by using genuine file-sharing websites, which aren’t often filtered or inspected in corporate contexts.

Impact

  • Information Theft
  • Security Bypass

Indicators of Compromise

MD5

  • 65143dff3771b9b126906932ebf35bba
  • b84ffd21f06c979629dc0fc025187b3e

SHA-256

  • 51d4d06407b684e4e0a28b8e29776fd00b83fd2835d2d9ec6dd70fbf90422991
  • 1fc33c19e24de2eeba58617b70f2a383907fe334ecfbf21f3c5b423a31d66170

SHA-1

  • 7edaacdf43ea270f278f40228d2f6e3d05cf4e56
  • b32933c8c66b44e30994e89671b38f8943b85755

Remediation

  • Block the threat indicators at their respective controls.
  • Search for IOCs in your environment.