Gootloader malware family
Gootloader is a malware family tracked by MalwareAnalyzer by Cyble across 4 publicly analyzed samples. First seen 2026-08-15, most recently 2026-08-24.
Corpus statistics
- Publicly analyzed samples: 4
- First seen: 2026-08-15
- Last seen: 2026-08-24
- Verdicts: suspicious 3, malicious 1
- File types: script 3, html 1
Extracted command-and-control infrastructure
- http://1.bp.blogspot.com/-YLR0ecFMGcU/T94oo4nsVQI/AAAAAAAAG6w/yu9ZK1o-n98/s1600/bg_content.gif - 1 sample
- http://3.bp.blogspot.com/-KSFSoZbUyyA/T-OYyR7Tp-I/AAAAAAAAG-A/6cQNNelsdV0/s1600/body-back.gif);color:#444444;font:x-small - 1 sample
- http://3.bp.blogspot.com/-NONrBLhghFk/To0nNB1LmkI/AAAAAAAAAI4/CAuzDfYiCiU/s1600/comment-arrow.gif - 1 sample
- http://3.bp.blogspot.com/-lSNZsuJNw-Y/ULITlX814FI/AAAAAAAAI2k/liRqSzbSgzI/s150/onizleme.png - 1 sample
- http://4.bp.blogspot.com/-POy-pvgzudE/Tz0SPxJXQnI/AAAAAAAAFUI/SlCAfDMFIhg/s1600/anonymous.jpg - 1 sample
- http://4.bp.blogspot.com/-lWVtT273JDo/T-OZdXNonjI/AAAAAAAAG-I/4VazQayimfI/s1600/header.jpg - 1 sample
- http://fullpornolariizle.blogspot.com/ - 1 sample
- http://fullpornolariizle.blogspot.com/favicon.ico - 1 sample
- http://fullpornolariizle.blogspot.com/feeds/posts/default - 1 sample
- http://fullpornolariizle.blogspot.com/feeds/posts/default?alt=rss - 1 sample
- http://gsgd.co.uk/sandbox/jquery/easing/ - 1 sample
- http://player.vimeo.com/video/45074303 - 1 sample
- http://quirksmode.org/mobile/tableViewport.html - 1 sample
- http://vimeo.com/40648169 - 1 sample
- http://vimeo.com/channels/staffpicks/38843628 - 1 sample
- http://vimeo.com/groups/surrealism/videos/36516384 - 1 sample
- http://www.abeautifulsite.net/detecting-mobile-devices-with-javascript/ - 1 sample
- http://www.maskolis.com/ - 1 sample
- http://www.metacafe.com/watch/7635964/dr_seuss_the_lorax_movie_trailer/ - 1 sample
- http://www.vrdmn.com/2013/07/overriding-jquerygetscript-to-include.html - 1 sample
Recent Gootloader samples
- b6e105c49523177a04f65400536984e35083f99b9597f92566a446f39ef5a3ce - malicious (2026-08-24)
- a219dfaf4b5acc45855fdd5fc1e5278f8614f257c1f4c99dd895c99e93fa476f - suspicious (2026-08-19)
- f1cbe5f24bb5373e39fa3abb363f16cfa5f9bf3475bc1e8cdef239051a3fa310 - suspicious (2026-08-19)
- 7c83cf241d34c75c75aa1d81bf333aac84089eac9caee853f50782060932cefa - suspicious (2026-08-15)
Frequently asked about Gootloader
- What is Gootloader?
- Gootloader is a malware family tracked by MalwareAnalyzer by Cyble across 4 publicly analyzed samples. First seen 2026-08-15, most recently 2026-08-24.
- How many Gootloader samples have been analyzed?
- MalwareAnalyzer by Cyble holds 4 publicly analyzed samples attributed to Gootloader, first seen 2026-08-15 and most recently 2026-08-24. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What file types does Gootloader use?
- Gootloader samples in this corpus are distributed as script (3), html (1).
- Does Gootloader use command-and-control infrastructure?
- Yes. 27 distinct command-and-control indicators have been extracted from Gootloader samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Gootloader malicious?
- 1 of 4 analyzed Gootloader samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends