PULSE NAME
Spoofed Saudi Purchase Order Drops GuLoader Executable to Deploy Malware Variants via Phishing Email
WHITE Malware Advisory SVThreatIntel 2022-05-26 Modified: 2022-05-26
12
IOCs
MEDIUM VOLUME
Researchers recently discovered an e-mail using a tactic where the message was delivered to a coffee company in Ukraine that an oil provider seemingly sent in Saudi Arabia. With the current fluctuations in the energy market and the related rise in prices for consumers, threat actors (TAs) are using lures to exploit the global interest. Affected platforms Windows. GuLoader executable Purporting to be a purchase order, the partial PDF file image displayed in the body of the email was actually a link to an ISO file. This file is hosted in the cloud that contained an executable for GuLoader. Also known as CloudEye and vbdropper, GuLoader dates to at least 2019. It is used to deploy malware variants like Agent Tesla, Formbook, and Lokibot.
Indicators of Compromise (12)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 487196ecd966622d96bd5ff5d6e39f00 MD5 of 4a1b6b30209c35ab180fa675a769e3285f54597963dd0bb29f7adb686ba88b79 2022-05-26
FileHash-MD5 c012417c6e5d2210fbe0bc36a79d577b MD5 of 14d52119459ef12be3a2f9a3a6578ee3255580f679b1b54de0990b6ba403b0fe 2022-05-26
FileHash-MD5 fc94d6d184bce05194888f5e968a4934 MD5 of c4debff9c0ec8a56aea5cd97215c6c906bd475ea8bd521fb9a346a4c992a0448 2022-05-26
FileHash-SHA1 041ef39a95c810daf4f02f80e3e858175bb1902e SHA1 of 14d52119459ef12be3a2f9a3a6578ee3255580f679b1b54de0990b6ba403b0fe 2022-05-26
FileHash-SHA1 8f68717be50c0ad2eadd130d90fac316b6505650 SHA1 of c4debff9c0ec8a56aea5cd97215c6c906bd475ea8bd521fb9a346a4c992a0448 2022-05-26
FileHash-SHA1 c7d86cbb53e2d271353bc2d6d0bfebfc78d20869 SHA1 of 4a1b6b30209c35ab180fa675a769e3285f54597963dd0bb29f7adb686ba88b79 2022-05-26
FileHash-SHA256 14d52119459ef12be3a2f9a3a6578ee3255580f679b1b54de0990b6ba403b0fe 2022-05-26
FileHash-SHA256 4a1b6b30209c35ab180fa675a769e3285f54597963dd0bb29f7adb686ba88b79 2022-05-26
FileHash-SHA256 c4debff9c0ec8a56aea5cd97215c6c906bd475ea8bd521fb9a346a4c992a0448 2022-05-26
URL http://bounceclick.live/VVB/COrg_RYGGqN229.binb 2022-05-26
domain bounceclick.live 2022-05-26
domain zoneofzenith.com 2022-05-26