logo

Dissecting the new shellcode-based variant of GuLoader (CloudEyE)

ID: 9393888c-182b-5a4b-8f33-fa8e38a58e8a

STIX ID: report--9393888c-182b-5a4b-8f33-fa8e38a58e8a

Feed Name: The Spamhaus Project

Threat Score
55/100

Date Published: 2022-10-12

Date Updated: 2026-04-30

Author: The Spamhaus Team

...
...

GuLoader leverages Windows vectored exception handlers (VEH) to change execution flow at runtime: it verifies the CONTEXT_RECORD for debug registers, checks for a 0xCC breakpoint at the exception EIP, XORs the following byte with 0xCB to compute the next EIP, and fills the bytes between with junk instructions to thwart static analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.