Gootloader
· Published 21/12/2025 03:26 · Modified 21/12/2025 07:44
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 03:26
- Modified
- 21/12/2025 07:44
- Updated at
- 21/12/2025 07:44
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 4 reports, 33 attack patterns (mitre), 3 malware, 1 sectors, 1 countries, 50 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (4)
-
6 MITREs 1 Malware 1 APT
-
6 MITREs 1 Malware 12 Observables 1 APT
-
2 Malwares 14 Observables 1 APT
-
8 MITREs 1 Malware 2 Observables 1 APT
Attack patterns (MITRE) (33)
-
T1566.002 usesSpearphishing Link MITRE
-
T1069 usesPermission Groups Discovery MITRE
-
T1059.005 usesVisual Basic MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1566.001 usesSpearphishing Attachment MITRE
-
T1055.012 usesProcess Hollowing MITRE
-
T1027.002 usesSoftware Packing MITRE
-
T1546.008 MITRE
-
T1078 usesValid Accounts MITRE
-
T1059.007 usesJavaScript MITRE
-
T1543.003 usesWindows Service MITRE
-
T1059.004 usesUnix Shell MITRE
Malware (3)
-
GootKit usesFamily
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Gootloader usesThe MITRE Corporation Confidence 100
[Gootloader](https://attack.mitre.org/software/S1138) is a Javascript-based infection framework that has been used since at least 2020 as a delivery method for the Gootkit banking trojan, [Cobalt Strike](https://attack.mitre.org/software/S0154), [REvil](https://attack.mitre.org/software/S0496), and others.…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (1)
-
Technology targets
Countries (1)
-
Australia targets
Indicators (50)
-
http://91.92.136.20:4001indicates -
playyourbeat.comindicates -
873dd1dcdfcbe9826b274c5880f5be81a878ee93715fbb18a654d9dba61c5dfcindicates -
metropole.com.auindicates -
68dd1a2da732d56b0618f8581502fcf209b1c828c97d05f239c98d55bb78b562indicates -
skhm.orgindicates -
http://91.215.85.143:443indicates -
f94048917ac75709452040754bb3d1a0aff919f7c2b4b42c5163c7bdb1fbf346indicates -
blog.lilianpraskova.czindicates -
lawliner.comindicates -
rkbaienfurt.deindicates -
artmodel.com.uaindicates