Rewterz Threat Alert – FormBook Malware – Active IOCs
March 18, 2022Rewterz Threat Alert – AZORult Malware – Active IOCs
March 18, 2022Rewterz Threat Alert – FormBook Malware – Active IOCs
March 18, 2022Rewterz Threat Alert – AZORult Malware – Active IOCs
March 18, 2022Severity
Medium
Analysis Summary
Since 2019, Guloader has been in operation as a downloader. GuLoader spreads through spam campaigns with malicious archived attachments. GuLoader downloads the bulk of malware, with the most frequent being AgentTesla, FormBook, and NanoCore. The encrypted payloads of this downloader are usually saved on Google Drive. It also acquired its payloads from Microsoft OneDrive and an attacker-controlled website.
GuLoader can avoid network-based detection by using genuine file-sharing websites, which aren’t often filtered or inspected in corporate contexts.
Impact
- Information Theft
- Security Bypass
Indicators of Compromise
MD5
- 65143dff3771b9b126906932ebf35bba
- b84ffd21f06c979629dc0fc025187b3e
SHA-256
- 51d4d06407b684e4e0a28b8e29776fd00b83fd2835d2d9ec6dd70fbf90422991
- 1fc33c19e24de2eeba58617b70f2a383907fe334ecfbf21f3c5b423a31d66170
SHA-1
- 7edaacdf43ea270f278f40228d2f6e3d05cf4e56
- b32933c8c66b44e30994e89671b38f8943b85755
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.