Keeping an eye on CloudEyE (GuLoader) - Reverse engineering the loader
ID: c3f68d5e-4400-5950-b12d-226d18e55e38
STIX ID: report--c3f68d5e-4400-5950-b12d-226d18e55e38
Feed Name: CERT Polska
Threat Score
This report provides a hands-on reverse-engineering walkthrough of the CloudEye/GuLoader Visual Basic downloader, demonstrating how to use IDA Pro to find the loader entry, convert embedded data into executable code, remove an XOR-encrypted wrapper, identify resolved APIs (via MSVBVM60 and VirtualAlloc), and extract the decrypted payload; a sample file hash and a small Python script for dumping the unpacked core are included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
