
GuLoader Hits EU Healthcare via Danish Temp Folder and Forged 2013 Timestamp
A Polish-language NSIS dropper posing as a procurement order stages 15 payloads — including JPEG-embedded shellcode carriers — into a Danish-named temp directory before beaconing to cPanel-hosted C2 nodes in Germany and Serbia. The campaign targets healthcare organisations in Poland and Croatia with a layered anti-forensic stack that achieves a 15/16 sandbox evasion rate.
A 673-kilobyte Windows executable with a Polish-language filename — Zamowienie_829522.bat, meaning "Order 829522" — is the entry point for one of the more technically deliberate GuLoader campaigns CTX Team has tracked against European healthcare targets. The file is a Nullsoft Installer self-extracting archive, flagged by 49 of 77 antivirus engines under the label trojan.makoob/nsis, and it arrives carrying a PE timestamp set to Christmas Day 2013 — a date approximately eleven years before the…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read