PULSE NAME
Spoofed Saudi Purchase Order Drops GuLoader Executable to Deploy Malware Variants via Phishing Email
WHITE Malware Advisory SVThreatIntel 2022-05-26 Modified: 2022-05-26
12
IOCs
MEDIUM VOLUME
Researchers recently discovered an e-mail using a tactic where the message was delivered to a coffee company in Ukraine that an oil provider seemingly sent in Saudi Arabia. With the current fluctuations in the energy market and the related rise in prices for consumers, threat actors (TAs) are using lures to exploit the global interest. Affected platforms Windows. GuLoader executable Purporting to be a purchase order, the partial PDF file image displayed in the body of the email was actually a link to an ISO file. This file is hosted in the cloud that contained an executable for GuLoader. Also known as CloudEye and vbdropper, GuLoader dates to at least 2019. It is used to deploy malware variants like Agent Tesla, Formbook, and Lokibot.
Indicators of Compromise (3 / 12 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 14d52119459ef12be3a2f9a3a6578ee3255580f679b1b54de0990b6ba403b0fe 2022-05-26
FileHash-SHA256 4a1b6b30209c35ab180fa675a769e3285f54597963dd0bb29f7adb686ba88b79 2022-05-26
FileHash-SHA256 c4debff9c0ec8a56aea5cd97215c6c906bd475ea8bd521fb9a346a4c992a0448 2022-05-26