Live Stream VOD: Guloader Shellcode Analysis (Patreon)
Published:
2022-12-20 04:54:21
Imported:
2023-09
Downloads
Content
In this twitch stream we take on Guloader. Our approach combines both static and dynamic analysis to bypass the the numerous anti-analysis techniques which make this malware infamous.
The stream goal is not a full analysis of all of the anti-analysis tricks (10 streams later lol) but instead we want to understand enough about the shell code to write our own static config extractor.
Sample
14d52119459ef12be3a2f9a3a6578ee3255580f679b1b54de0990b6ba403b0fe
Notes
Private Config Extraction Algorithm
We have decided not to publicly publish this algorithm as the Guloader developers actively monitor and respond to reports on their malware. But we have attached our private notebook with the simple brute force algorithm we developed on stream.