logo

Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)

ID: 4d7a5a8a-bf1a-59f2-88d3-c818d212782a

STIX ID: report--4d7a5a8a-bf1a-59f2-88d3-c818d212782a

Feed Name: SANS ISC Diary

Threat Score
65/100

Date Published: 2026-09-01

Date Updated: 2026-09-15

...
...

This report documents a lab-confirmed Guildma (Astaroth) infection delivered by a Brazil-geofenced Portuguese phishing link that required Brazilian locale settings; the initial ZIP contained a shortcut that saved a DLL to an NTFS alternate data stream and installed an AutoIt-based persistent payload. The write-up provides IOCs (SHA-256 hashes, filenames, file locations), malicious domains, and network traffic observations to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.