logo

Getting gooey with GULOADER: deobfuscating the downloader

ID: 97a0115d-0ff0-53cf-b3eb-869d3deda61a

STIX ID: report--97a0115d-0ff0-53cf-b3eb-869d3deda61a

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2023-12-06

Date Updated: 2026-04-27

...
...

Elastic Security Labs presents a technical analysis of GULOADER (CloudEyE), an evasive shellcode downloader delivered via NSIS that embeds encrypted shellcode and uses callback-based execution and an enhanced Vectored Exception Handler (VEH) — including privileged/illegal-instruction exceptions — to corrupt control flow and thwart analysis; the report explains techniques to find the real shellcode entrypoint (using Miasm and x64dbg), how VEH modifies EIP via a CONTEXT-based XOR/offset algorithm, and offers a methodology and tools (TinyTracer, IDAPython patching, YARA rules) plus IOCs (sample SHA-256, C2 IP/URL) to detect and clean the control flow.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.