Guloader Malware Being Disguised as Employee Performance Reports
ID: 087ce831-9b36-5e23-82ec-55842ad79b32
STIX ID: report--087ce831-9b36-5e23-82ec-55842ad79b32
Feed Name: ASEC
AhnLab ASEC identified a phishing campaign delivering Guloader via a RAR attachment named "staff record pdf.exe" (disguised as a PDF). The loader downloads shellcode from a Google Drive URL and deploys Remcos RAT (C2: 196.251.116.219:2404,5000), providing remote access and data-theft capabilities (keylogging, screenshots, browser credential theft). The report includes the malware MD5 (c95f2a7556902302f352c97b7eed4159), the download URL, and guidance to exercise caution with email attachments and change passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
