← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Spoofed Saudi Purchase Order Drops GuLoader Executable to Deploy Malware Variants via Phishing Email
Researchers recently discovered an e-mail using a tactic where the message was delivered to a coffee company in Ukraine that an oil provider seemingly sent in Saudi Arabia. With the current fluctuations in the energy market and the related rise in prices for consumers, threat actors (TAs) are using lures to exploit the global interest.
Affected platforms
Windows.
GuLoader executable
Purporting to be a purchase order, the partial PDF file image displayed in the body of the email was actually a link to an ISO file. This file is hosted in the cloud that contained an executable for GuLoader. Also known as CloudEye and vbdropper, GuLoader dates to at least 2019. It is used to deploy malware variants like Agent Tesla, Formbook, and Lokibot.
Indicators of Compromise (12)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 487196ecd966622d96bd5ff5d6e39f00 | MD5 of 4a1b6b30209c35ab180fa675a769e3285f54597963dd0bb29f7adb686ba88b79 | 2022-05-26 | |
| FileHash-MD5 | c012417c6e5d2210fbe0bc36a79d577b | MD5 of 14d52119459ef12be3a2f9a3a6578ee3255580f679b1b54de0990b6ba403b0fe | 2022-05-26 | |
| FileHash-MD5 | fc94d6d184bce05194888f5e968a4934 | MD5 of c4debff9c0ec8a56aea5cd97215c6c906bd475ea8bd521fb9a346a4c992a0448 | 2022-05-26 | |
| FileHash-SHA1 | 041ef39a95c810daf4f02f80e3e858175bb1902e | SHA1 of 14d52119459ef12be3a2f9a3a6578ee3255580f679b1b54de0990b6ba403b0fe | 2022-05-26 | |
| FileHash-SHA1 | 8f68717be50c0ad2eadd130d90fac316b6505650 | SHA1 of c4debff9c0ec8a56aea5cd97215c6c906bd475ea8bd521fb9a346a4c992a0448 | 2022-05-26 | |
| FileHash-SHA1 | c7d86cbb53e2d271353bc2d6d0bfebfc78d20869 | SHA1 of 4a1b6b30209c35ab180fa675a769e3285f54597963dd0bb29f7adb686ba88b79 | 2022-05-26 | |
| FileHash-SHA256 | 14d52119459ef12be3a2f9a3a6578ee3255580f679b1b54de0990b6ba403b0fe | — | 2022-05-26 | |
| FileHash-SHA256 | 4a1b6b30209c35ab180fa675a769e3285f54597963dd0bb29f7adb686ba88b79 | — | 2022-05-26 | |
| FileHash-SHA256 | c4debff9c0ec8a56aea5cd97215c6c906bd475ea8bd521fb9a346a4c992a0448 | — | 2022-05-26 | |
| URL | http://bounceclick.live/VVB/COrg_RYGGqN229.binb | — | 2022-05-26 | |
| domain | bounceclick.live | — | 2022-05-26 | |
| domain | zoneofzenith.com | — | 2022-05-26 |