GuLoader Malware Obfuscation Techniques Analyzed
ID: 66399199-388f-577a-ac1c-75f3eb02395f
STIX ID: report--66399199-388f-577a-ac1c-75f3eb02395f
Feed Name: Zscaler Security Research Blog
This report provides a technical analysis of GuLoader, detailing its polymorphic constant construction, multiple exception-based control-flow obfuscation techniques (software breakpoints, single-step, access violation, illegal/privileged instruction handlers), dynamic DJB2-based hashing, encrypted string handling (static and stack-based), payload decryption using large XOR keys with cloud-hosted payloads, and accompanying IDA scripts developed by ThreatLabz to aid deobfuscation and analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
