Researcher for Gootloader malware's Avatar

Researcher for Gootloader malware

@gootloader.zip

https://gootloader.wordpress.com/

120
Followers
5
Following
637
Posts
11.05.2023
Joined
Posts Following

Latest posts by Researcher for Gootloader malware @gootloader.zip

Preview
🚨Gootloader Returns: Malware Hidden in Google Ads for Legal Documents The threat actor behind the Gootloader malware has once again changed their tactics, but also reverted to some of their old ways. Just like with the previous infection method, we are seeing Google …

⚠️ New TTPs detected for #Gootloader ⚠️
Out are the PDF conversions and back in are legal document lurs. They are still using #malvertising, not SEO poisoning.

gootloader.wordpress.com/2025/03/31/g...

31.03.2025 13:37 πŸ‘ 5 πŸ” 3 πŸ’¬ 0 πŸ“Œ 2
Preview
Tools/jQuery-GootloaderJSv2.yar at main Β· GootloaderSites/Tools Contribute to GootloaderSites/Tools development by creating an account on GitHub.

Created a new #yara rule for #gootloader, thanks to @malwrhunterteam.bsky.social smica83. github.com/GootloaderSi...

18.12.2024 21:53 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Gootloader’s Pivot from SEO Poisoning: PDF Converters Become the New Infection Vector Three weeks ago, Gootloader samples suddenly dried up. This has happened before, so I switched VPNs and tried new locationsβ€”coffee shops, friends’, and family’s Wi-Fi networksβ€”but still couldn’t re…

Sorry I haven’t been active over here. Here is my latest blog update regarding Gootloader’s massive change in tactics from SEO poisoning to PDF converters gootloader.wordpress.com/2024/11/07/g...

19.11.2024 19:34 πŸ‘ 5 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.penhaligonsfriends.org.uk/api.php

01.02.2024 04:10 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.peleg.cn/api.php

01.02.2024 03:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.pedrademari.com/api.php

01.02.2024 03:30 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.papingo.gr/api.php

01.02.2024 03:10 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.nwcc-apha.com/api.php

01.02.2024 01:30 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.nomik.at/api.php

01.02.2024 01:25 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.nilsfuncke.se/api.php

01.02.2024 01:07 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.nightlightproductions.co.uk/api.php

01.02.2024 00:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.nico-bloxx.de/api.php

01.02.2024 00:25 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.neretva.se/api.php

01.02.2024 00:06 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.nashitalia.com/api.php

31.01.2024 23:02 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.nada-editions.fr/api.php

31.01.2024 22:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.nada-editions.fr/api.php

31.01.2024 22:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.my-cfecgc-aed.fr/api.php

31.01.2024 22:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.mobilcare-mintraching.de/api.php

31.01.2024 22:22 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.minorihoikuen.ed.jp/api.php

31.01.2024 22:10 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.metromediasystem.it/api.php

31.01.2024 22:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.messagesmusicaux.com/api.php

31.01.2024 21:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.meinlieblingsglas.de/api.php

31.01.2024 21:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.meibachtech.com/api.php

31.01.2024 21:30 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.medischdrukwerk.nl/api.php

31.01.2024 21:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.media-web24.de/api.php

31.01.2024 20:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.marmolesdelnervion.com/api.php

31.01.2024 20:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.marktastic.com/api.php

31.01.2024 19:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.marekstejskal.cz/api.php

31.01.2024 19:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.mammadu.org/api.php

31.01.2024 19:10 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Current GootLoader site, serving up malicious zip/js is
hxxps://www.malfant-masson-genealogie.fr/api.php

31.01.2024 19:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0