This article analyzes a Guildma (also known as Astaroth) malware infection originating from a Brazilian Portuguese phishing email. Guildma is a sophisticated banking trojan primarily targeting Brazilian users and organizations. The malware is typically distributed via spam email campaigns written in Brazilian Portuguese to target local victims. Astaroth/Guildma is known for its use of living-off-the-land binaries (LOLBins) to evade detection and execute its payload. The infection chain often involves malicious attachments or links leading to multi-stage loaders. This malware is capable of credential theft, keylogging, and intercepting banking transactions. The article was published on September 1st and appears on the SANS Internet Storm Center diary.