Security & Threat Intelligence · 01.09.2026, 00:47 UTC
Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
| Schweregrad | info |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | SANS Internet Storm Center ↗ |
| Veröffentlicht | 01.09.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Introduction
On Monday 2026-08-31, I used a link from a malicious Brazilian Portuguese email to infect a Windows host in my lab. This was a Guildma (Astaroth) malware infection.
The link from the email is geofenced for Brazil, meaning that it would only deliver the malware if I checked it from a Brazil-based IP address. Otherwise, it would send a legitimate installer (in this case for Android Studio) and not the malware. Furthermore, my web browser and operating system needed to use Brazilian Portuguese language settings and Brazil regional settings.
The initial downloaded file was a zip archive that contained a Windows shortcut. The shortcut retrieved content from a web server and saved it as an atlernate data stream to a file created under the user's AppData\Local\Temp directory. This alternate data stream contained a 64-bit DLL file that doesn't appear to be malicious, but it was used to retrieve and install an AutoIt package for Guildma malware.
Today's diary shares indicators from the activity. Of note, many of the specific indicators like some of the SHA-256 hashes appear to be unique for this particular infection.
Images From the Infection
Shown above: Screenshot of the email.
Shown above: Malicious file downloaded from link in the email.
Shown above: Traffic from the infection filtered in Wireshark.
Shown above: Malware persistent on the infected Windows host.
Indicators of the Activity
Select headers from the email:
Received: from relatorio01a.colombstracciatella.cfd (unknown [185.254.222.105]) [information removed]; Wed, 26 Aug 2026 22:01:41 +0000 …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- info AWS Workload Credentials Provider is now available as a one-click install for Linux and Windows
- info AWS Elastic Beanstalk now supports Active Directory domain join for Windows Server environments
- info PolicyLong: Towards On-Policy Context Extension
- info Characterization of Request and Token Energy Costs for LLM Inference Workloads on GPU Platforms