GuLoader - S0561
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:36
- Modified
- 20/12/2025 22:27
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 74 attack patterns (mitre), 1 intrusion sets (apt), 9 sectors, 8 countries, 99 indicators, 9 vulnerabilities (cve), 7 reports
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (74)
-
T1083 usesFile and Directory Discovery MITRE
-
T1087 usesAccount Discovery MITRE
-
T1071.001 usesWeb Protocols MITRE
-
T1204 usesUser Execution MITRE
-
T1032 uses
-
T1105 usesIngress Tool Transfer MITRE
-
T1210 usesExploitation of Remote Services MITRE
-
T1106 usesNative API MITRE
-
T1486 usesData Encrypted for Impact MITRE
-
T1057 usesProcess Discovery MITRE
-
T1023 uses
-
T1574 usesHijack Execution Flow MITRE
Intrusion sets (APT) (1)
-
Makop usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (9)
-
Technology targets
-
Education targets
-
Engineering consulting targets
-
Information Technologies Consulting targets
-
Finance targets
-
Energy targets
-
Consulting targets
-
Manufacturing targets
-
Government targets
Countries (8)
-
United States of America targets
-
Germany targets
-
Czechia targets
-
British Indian Ocean Territory targets
-
India targets
-
Brazil targets
-
Spain targets
-
Croatia targets
Indicators (99)
-
stix 100/100 Revoked
Win.Tool.ShareScanner-6827521-0 SHA256 of 597de376b1f80c06d501415dd973dcec
· Valid until 15/05/2026 · Source: AlienVault -
stix 100/100· Valid until 06/12/2026 · Source: AlienVault
-
stix 100/100· Valid until 06/12/2026 · Source: AlienVault
-
stix 100/100· Valid until 06/12/2026 · Source: AlienVault
-
newsbloger1.duckdns.orgindicatesstix 100/100 Revoked· Valid until 09/03/2026 · Source: AlienVault -
stix 100/100 Revoked· Valid until 14/11/2025 · Source: AlienVault
-
http://45.137.117.184/riBOkPd173.mixindicatesstix 100/100 Revoked· Valid until 07/12/2022 · Source: AlienVault -
stix 100/100· Valid until 06/02/2027 · Source: AlienVault
-
https://rosenbaum.live/bars.phpindicatesstix 100/100 Revoked· Valid until 20/05/2025 · Source: AlienVault -
stix 100/100 Revoked· Valid until 04/11/2025 · Source: AlienVault
Vulnerabilities (CVE) (9)
Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.
- Published
- 07/04/2023
- Modified
- 21/12/2025
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this …
- Published
- 28/01/2022
- Modified
- 21/12/2025
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, …
- Attack vector
- LOCAL
- Published
- 22/05/2020
- Modified
- 21/12/2025
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
- Published
- 03/03/2022
- Modified
- 21/12/2025
Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully …
- Published
- 03/03/2025
- Modified
- 20/12/2025
Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 12/05/2017
- Modified
- 22/04/2026
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An …
- Published
- 10/02/2022
- Modified
- 20/12/2025
A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. …
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 09/03/2016
- Modified
- 22/04/2026
ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. …
- Published
- 20/12/2025
- Modified
- 21/12/2025
Reports (7)
-
AlienVault Confidence 100 20 MITREs 5 Malwares 12 IOCs 12 Observables
-
14 MITREs 2 Malwares 6 Observables
-
2 Malwares 2 Observables
-
10 CVEs 18 MITREs 4 Malwares 62 Observables 1 APT
-
15 MITREs 5 Malwares 1 APT
-
19 MITREs 5 Malwares 13 Observables
-
10 MITREs 2 Malwares 2 Observables