New Gholee samples spotted in the wild, of course AV don't detect them.
https://www.virustotal.com/en/file/84334c2e5c4efb898969c6f2e282db560585e2483d5bc4c7c377995b0f72d7c2/analysis/ (2 / 57)
https://www.virustotal.com/en/file/4a6dead9758938276fe092e06c64028429e2776a219b47263d51c28a9cc3aa8d/analysis/ (2 / 57)
https://www.virustotal.com/en/file/39e57bab41b590ab5e8620f30a77cd30794624b4a8e2b65bd5d2c7a00ffa5312/analysis/ (1 / 57)
Previous info:
Introducing Gholee - http://securityaffairs.co/wordpress/28170/cyber-crime/gholee-malware.htm
Shared samples - https://pastebin.com/C5YpKX4Y
Yara rule - https://pastebin.com/fm1mb6qX
Malicious Macro - https://pastebin.com/Kz45uVma
Comments