s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.gootloader

📛 Threat Title

Malware family: GootLoader

Category: GootLoader First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.gootloader`. Printable name: GootLoader. Aliases: SLOWPOUR.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.gootloader VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.gootloader

IOC database

Type
domain
Value
js.gootloader
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.gootloader

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.gootloader

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as GootLoader .

  • web:cloud.google.com

    Since January 2021, Mandiant Managed Defense has consistently responded to GOOTLOADER infections. Threat actors cast a widespread net when spreading GOOTLOADER and impact a wide range of industry verticals and geographic regions. We currently only attribute GOOTLOADER malware and infrastructure to a group we track as UNC2565, and we believe it to be exclusive to this group.

  • web:cyberpress.org

    Gootloader malware continues to evade detection, bypassing most security tools while maintaining a low detection rate.

  • web:cybersecsentinel.com

    Threat Group - UNC2565 (also tracked as Storm-0494) Threat Type - Malware Loader and Initial Access Platform Exploited Vulnerabilities - No specific CVE confirmed. Campaign relies on SEO poisoning, compromised WordPress sites, archive format inconsistencies, Windows Script Host execution, and legacy filename behaviour. Malware Used - GootLoader , GootBot, secondary payloads such as ...

  • web:dailysecurityreview.com

    The Gootloader malware gang has resurfaced after months of inactivity, reviving its signature SEO poisoning attacks. By manipulating search results to distribute malicious downloads through fake forum pages, the group continues to target business users with stealthy, region-specific malware delivery campaigns.

  • web:hivepro.com

    Return of Gootloader : Blending Technical Evasion with Operational Discipline Summary Gootloader malware has re-emerged with renewed and aggressive operations starting October 27, 2025, targeting organizations worldwide through sophisticated SEO poisoning and compromised WordPress sites. The latest Gootloader campaigns demonstrate rapid operational efficiency, achieving domain controller ...

  • web:redcanary.com

    Gootloader is a pervasive threat affecting enterprise organizations. This blog includes malware analysis and detection opportunities.

  • web:thehackernews.com

    The JavaScript (aka JScript) malware loader called GootLoader has been observed using a malformed ZIP archive that's designed to sidestep detection efforts by concatenating anywhere from 500 to 1,000 archives. "The actor creates a malformed archive as an anti-analysis technique," Expel security ...

  • web:www.huntress.com

    Overview Gootloader is a sophisticated JavaScript-based malware loader that threat actors commonly use to gain initial access. This malware is typically delivered when users visit compromised websites, with threat actors leveraging SEO poisoning to drive traffic to these sites.

  • web:www.microsoft.com

    Gootloader is an initial access malware family that traces its lineage to the Gootkit banking trojan. It now operates as an Initial-Access-as-a-Service (IAaaS) platform for ransomware affiliates. The malware uses a multi-stage JavaScript architecture and only delivers its full payload to Windows devices joined to Active Directory domains.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.