Dissecting the new shellcode-based variant of GuLoader (CloudEyE)
ID: 9393888c-182b-5a4b-8f33-fa8e38a58e8a
STIX ID: report--9393888c-182b-5a4b-8f33-fa8e38a58e8a
Feed Name: The Spamhaus Project
Threat Score
GuLoader leverages Windows vectored exception handlers (VEH) to change execution flow at runtime: it verifies the CONTEXT_RECORD for debug registers, checks for a 0xCC breakpoint at the exception EIP, XORs the following byte with 0xCB to compute the next EIP, and fills the bytes between with junk instructions to thwart static analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
