Guloader URLs listed by URLhaus
GuLoader installs other malware. Removing its first file may leave the malware it already downloaded on the device.
Background
CrowdStrike's investigation documented email attachments delivering GuLoader, which then fetched malware including FormBook, Agent Tesla and NanoCore. Those were observed payloads in that investigation, not a promise that every GuLoader file installs the same thing.
What to do
If your antivirus reports GuLoader, open its detection history to see whether the threat was blocked, quarantined or still needs action. If you use Microsoft Defender on Windows, open Windows Security > Virus & threat protection > Protection history. If the status is Threat found - action needed, follow Defender's recommended action. Threat blocked means Defender reports it removed that threat. Keep a quarantined file quarantined; do not choose Allow on device.
If GuLoader ran, ask IT to check for additional malware it downloaded and launched. On a personal Windows device, run a full antivirus scan and follow the removal instructions for every detection. If a password stealer is found to have run, secure the affected accounts from a clean device. Deleting the original attachment alone is not sufficient.
Feed records
This report links to a URLhaus record for a reported malware download address. The background above was checked on 2026-09-08; the feed records have their own observation dates.
References
- urlhaus.abuse.ch · hxxps://drive[.]google[.]com/uc?export=download&id=1Oo3B9NwXjOYvxUPrWdwwAF6k906_Gz0T indicator url
- urlhaus.abuse.ch · hxxps://drive[.]google[.]com/uc?export=download&id=1fshZMT3FceUeQeZJDnYCvzsuGeCKfVFN indicator url
- urlhaus.abuse.ch · hxxps://drive[.]google[.]com/uc?export=download&id=1mVI9h_rV6mptfRqbC3cDNiyfurIAq2tQ indicator url