GULoader Campaigns: A Deep Dive Analysis of a highly evasive Shellcode based loader
ID: d0df9a27-f60d-5200-8c41-920f044238cd
STIX ID: report--d0df9a27-f60d-5200-8c41-920f044238cd
Feed Name: McAfee Labs Blog
This report provides a detailed technical analysis of GULoader (GUloader) campaigns: NSIS-based malspam delivery, plugin DLLs that load and decode shellcode, extensive Vectored Exception Handling and runtime padding anti-analysis techniques, process hollowing/code injection into CasPol.exe (or child processes), and final payload retrieval and deobfuscation (commonly deploying stealers like Vidar, Raccoon, and Remcos RAT). The analysis includes resolved API usage, anti-dump and anti-analysis behavior, decoding routines, and a list of observed IOCs (hashes) useful for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
