ZeroHour
SANS Internet Storm Centerpublished ()ingested

Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)

mediumMalware exploited in the wildimportance 45
AI summary · glm-5.3-flash

Guildma (Astaroth) malware spread via geofenced Brazilian Portuguese phishing emails, using zip archives, shortcuts, and AutoIt loaders.

SANS researchers documented a Guildma (Astaroth) malware infection initiated on 2026-08-31 by a malicious Brazilian Portuguese email offering a DocuSign-themed PDF. The delivery link is geofenced to Brazil and requires Brazilian Portuguese browser and OS language settings, otherwise serving a legitimate installer. The infection chain uses a zip archive containing a Windows shortcut that retrieves a DLL saved as an alternate data stream, which installs a compiled AutoIt package for persistence. Unique SHA-256 indicators and HTTPS traffic to Azure-hosted and .cfd domains were observed, with prior reports noting the campaign's abuse of GitHub.

  • Guildma/Astaroth infection via Brazilian Portuguese email with DocuSign lure
  • Geofenced delivery: only Brazil IPs with Portuguese settings receive the malware
  • Chain: zip archive > Windows shortcut > DLL in alternate data stream > AutoIt loader
  • Malware persists under C:\Users\Public\Libraries\.cache\PLAX\; prior campaign abused GitHub

Indicators of compromiseAll →

TypeIndicatorContext
domainaguamammillaria.cfdh4htc0h0ggdh.canadacentral-01.azurewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain:
domainaguasedum.cfdurewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pingg
domainazurewebsites.nete text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortcut: S
domaincolombstracciatella.cfdr: "Contrato Via Docusing" <[email protected][.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: Assine co
domainpinggy.linkm[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pinggy[.]link:21601/ Note: I saw HTTPS traffic to WhatsApp and GitHub d
email[email protected]2026 22:01:41 +0000 (UTC) Sender: "Contrato Via Docusing" <[email protected][.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: Assin
ipv4185.254.222.105ceived: from relatorio01a.colombstracciatella.cfd (unknown [185.254.222.105]) [information removed] ; Wed, 26 Aug 2026 22:01:41 +0000 (
sha25647d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911e: Zip archive data, at least v2.0 to extract SHA-256 hash: 47d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911 File size: 1,553 bytes File name: 868283789726483.lNk File
sha256a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63cahe infection, doesn't appear to be malicious: SHA-256 hash: a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63ca File size: 266,242 bytes File type: PE32+ executable (DLL)
sha256cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869d zip archive and extracted Windows shortcut: SHA-256 hash: cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869 File size: 1,661 bytes File name: 868283789726483.zip File
sha256f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4It script for the persistent Guildma malware: SHA-256 hash: f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4 File size: 277,874 bytes File type: Data File location: C:\
urlhttps://sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[684.BPSE.CONTRATOS.DIGITAIS.pdf Link from the message text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortc
Full article452 words · extracted from isc.sans.edu · click to collapse

Introduction

On Monday 2026-08-31, I used a link from a malicious Brazilian Portuguese email to infect a Windows host in my lab. This was a Guildma (Astaroth) malware infection.

The link from the email is geofenced for Brazil, meaning that it would only deliver the malware if I checked it from a Brazil-based IP address. Otherwise, it would send a legitimate installer (in this case for Android Studio) and not the malware. Furthermore, my web browser and operating system needed to use Brazilian Portuguese language settings and Brazil regional settings.

The initial downloaded file was a zip archive that contained a Windows shortcut. The shortcut retrieved content from a web server and saved it as an alternate data stream to a file created under the user's AppData\Local\Temp directory. This alternate data stream contained a 64-bit DLL file that doesn't appear to be malicious, but it was used to retrieve and install an AutoIt package for Guildma malware.

Today's diary shares indicators from the activity. Of note, many of the specific indicators like some of the SHA-256 hashes appear to be unique for this particular infection.

Images From the Infection

Shown above: Screenshot of the email.

Shown above: Malicious file downloaded from link in the email.

Shown above: Traffic from the infection filtered in Wireshark.

Shown above: Malware persistent on the infected Windows host.

Indicators of the Activity

Select headers from the email:

Received: from relatorio01a.colombstracciatella.cfd (unknown [185.254.222.105]) [information removed] ; Wed, 26 Aug 2026 22:01:41 +0000 (UTC)

Sender: "Contrato Via Docusing" <[email protected][.]cfd>

Date: Wed, 26 Aug 2026 19:01:16 -0300

Subject: Assine com o Docusing: CONTRATO_ASSINATURA_FINAL.40572684.BPSE.CONTRATOS.DIGITAIS.pdf

Link from the message text:

hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/

Downloaded zip archive and extracted Windows shortcut:

SHA-256 hash: cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869

File size: 1,661 bytes

File name: 868283789726483.zip

File type: Zip archive data, at least v2.0 to extract

SHA-256 hash: 47d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911

File size: 1,553 bytes

File name: 868283789726483.lNk

File type: MS Windows shortcut

DLL saved as an alternate data stream during the infection, doesn't appear to be malicious:

SHA-256 hash: a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63ca

File size: 266,242 bytes

File type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows

File location: C:\Users\ [username] \AppData\Local\Temp\n1LUQ7.log:h6JSb

Compiled AutoIt script for the persistent Guildma malware:

SHA-256 hash: f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4

File size: 277,874 bytes

File type: Data

File location: C:\Users\Public\Libraries\.cache\PLAX\Beatz.LEDPRO.09662.8729.422.log

Domains the infected Windows host communicated with over HTTPS (TCP port 443):

ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net

plosancol.aguamammillaria[.]cfd

crironxil.aguasedum[.]cfd

TCP traffic to another domain:

tcp[:]//omzagdmspc.a.pinggy[.]link:21601/

Note: I saw HTTPS traffic to WhatsApp and GitHub domains later during this infection, but those are legitimate domains, so I didn't include them in this write-up. A previous article has noted this campaign abusing GitHub, so I've included the mention here.

Bradley Duncan

brad [at] malware-traffic-analysis.net

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Text extracted automatically; images, tables and formatting may be missing. Original: https://isc.sans.edu/diary/rss/33300