A DNS Investigation of the GootLoader Campaign
It’s one thing for a piece of malware to steal victims’ data. It gets worse, though, when that malware paves the way for even more sinister actions like dropping a ransomware or allowing further compromise without getting detected. That’s the case for GootLoader.1
Twelve domains have been tagged as GootLoader indicators of compromise (IoCs).2 The WhoisXML API expanded this list to uncover other connected artifacts and found: