Gootloader malware family
Gootloader is a malware family tracked by MalwareAnalyzer by Cyble across 5 publicly analyzed samples. First seen 2026-08-15, most recently 2026-08-25.
Corpus statistics
- Publicly analyzed samples: 5
- First seen: 2026-08-15
- Last seen: 2026-08-25
- Verdicts: suspicious 3, malicious 2
- File types: script 3, html 2
Extracted command-and-control infrastructure
- http://www.maskolis.com/ - 2 samples
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css - 2 samples
- http://1.bp.blogspot.com/-YLR0ecFMGcU/T94oo4nsVQI/AAAAAAAAG6w/yu9ZK1o-n98/s1600/bg_content.gif - 1 sample
- http://2.bp.blogspot.com/-uitX7ROPtTU/Tyv-G4NA_uI/AAAAAAAAFBY/NcWLPVnYEnU/s1600/no+image.jpg - 1 sample
- http://3.bp.blogspot.com/-KSFSoZbUyyA/T-OYyR7Tp-I/AAAAAAAAG-A/6cQNNelsdV0/s1600/body-back.gif);color:#444444;font:x-small - 1 sample
- http://3.bp.blogspot.com/-NONrBLhghFk/To0nNB1LmkI/AAAAAAAAAI4/CAuzDfYiCiU/s1600/comment-arrow.gif - 1 sample
- http://3.bp.blogspot.com/-lSNZsuJNw-Y/ULITlX814FI/AAAAAAAAI2k/liRqSzbSgzI/s150/onizleme.png - 1 sample
- http://4.bp.blogspot.com/-POy-pvgzudE/Tz0SPxJXQnI/AAAAAAAAFUI/SlCAfDMFIhg/s1600/anonymous.jpg - 1 sample
- http://4.bp.blogspot.com/-lWVtT273JDo/T-OZdXNonjI/AAAAAAAAG-I/4VazQayimfI/s1600/header.jpg - 1 sample
- http://fullpornolariizle.blogspot.com/ - 1 sample
- http://fullpornolariizle.blogspot.com/favicon.ico - 1 sample
- http://fullpornolariizle.blogspot.com/feeds/posts/default - 1 sample
- http://fullpornolariizle.blogspot.com/feeds/posts/default?alt=rss - 1 sample
- http://gsgd.co.uk/sandbox/jquery/easing/ - 1 sample
- http://musikmp3pilihan.blogspot.com/search/label/Campursari - 1 sample
- http://musikmp3pilihan.blogspot.com/search/label/Dangdut - 1 sample
- http://musikmp3pilihan.blogspot.com/search/label/Pop%20Indonesia - 1 sample
- http://musikmp3pilihan.blogspot.com/search/label/Pop%20Sunda - 1 sample
- http://musikmp3pilihan.blogspot.com/search/label/Religi - 1 sample
- http://musikmp3pilihan.blogspot.com/search/label/slowrock%20indonesia - 1 sample
Recent Gootloader samples
- 7b9c9f7b866f9a6efbc14a3e7fa5bceeb82efb9da7e929b0b3d45e0981461ab3 - malicious (2026-08-25)
- b6e105c49523177a04f65400536984e35083f99b9597f92566a446f39ef5a3ce - malicious (2026-08-24)
- a219dfaf4b5acc45855fdd5fc1e5278f8614f257c1f4c99dd895c99e93fa476f - suspicious (2026-08-19)
- f1cbe5f24bb5373e39fa3abb363f16cfa5f9bf3475bc1e8cdef239051a3fa310 - suspicious (2026-08-19)
- 7c83cf241d34c75c75aa1d81bf333aac84089eac9caee853f50782060932cefa - suspicious (2026-08-15)
Frequently asked about Gootloader
- What is Gootloader?
- Gootloader is a malware family tracked by MalwareAnalyzer by Cyble across 5 publicly analyzed samples. First seen 2026-08-15, most recently 2026-08-25.
- How many Gootloader samples have been analyzed?
- MalwareAnalyzer by Cyble holds 5 publicly analyzed samples attributed to Gootloader, first seen 2026-08-15 and most recently 2026-08-25. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What file types does Gootloader use?
- Gootloader samples in this corpus are distributed as script (3), html (2).
- Does Gootloader use command-and-control infrastructure?
- Yes. 41 distinct command-and-control indicators have been extracted from Gootloader samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Gootloader malicious?
- 2 of 5 analyzed Gootloader samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends