Getting gooey with GULOADER: deobfuscating the downloader
ID: 97a0115d-0ff0-53cf-b3eb-869d3deda61a
STIX ID: report--97a0115d-0ff0-53cf-b3eb-869d3deda61a
Feed Name: Elastic Security Labs
Elastic Security Labs presents a technical analysis of GULOADER (CloudEyE), an evasive shellcode downloader delivered via NSIS that embeds encrypted shellcode and uses callback-based execution and an enhanced Vectored Exception Handler (VEH) — including privileged/illegal-instruction exceptions — to corrupt control flow and thwart analysis; the report explains techniques to find the real shellcode entrypoint (using Miasm and x64dbg), how VEH modifies EIP via a CONTEXT-based XOR/offset algorithm, and offers a methodology and tools (TinyTracer, IDAPython patching, YARA rules) plus IOCs (sample SHA-256, C2 IP/URL) to detect and clean the control flow.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
