Dissecting GootLoader With Node.js
ID: 189a121c-05f1-5782-960e-f8a6526a7f4f
STIX ID: report--189a121c-05f1-5782-960e-f8a6526a7f4f
Feed Name: Palo Alto Networks Unit 42
Threat Score
This Unit42 report analyzes GootLoader JavaScript malware that uses long function-array loops and counter thresholds to delay and evade sandbox analysis, details an infection chain via fake forum posts and ZIP-delivered JS, provides deobfuscated code excerpts and IOCs (SHA256 hashes), and recommends detection and response measures for affected organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
