Live Stream VOD: Guloader ( Part 3 ) String Decryption and Debugging (Patreon)
Published:
2023-01-13 19:19:47
Imported:
2023-09
Content
In this twitch stream we take a third look at Guloader and begin our analysis of the final stage shell code. The code has been updated from the first sample we looked at but some of the same structure is present which helps with analysis (bindiff!).
Heads up: Once we get stuck on trying to find the decryption key you can skip to the end and save yourself some time 😂 but there are a few tricks that might be interesting if you watch the full way though (dead lock debugger attach).
Sample
E3A8356689B97653261EA6B75CA911BC65F523025F15649E87B1AEF0071AE107