logo

Keeping an eye on CloudEyE (GuLoader) - Reverse engineering the loader

ID: c3f68d5e-4400-5950-b12d-226d18e55e38

STIX ID: report--c3f68d5e-4400-5950-b12d-226d18e55e38

Feed Name: CERT Polska

Threat Score
65/100

Date Published: 2021-04-13

Date Updated: 2026-04-19

Author: Michał Praszmo

...
...

This report provides a hands-on reverse-engineering walkthrough of the CloudEye/GuLoader Visual Basic downloader, demonstrating how to use IDA Pro to find the loader entry, convert embedded data into executable code, remove an XOR-encrypted wrapper, identify resolved APIs (via MSVBVM60 and VirtualAlloc), and extract the decrypted payload; a sample file hash and a small Python script for dumping the unpacked core are included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.