ATT&CKReferencesMedium Eli Salem GuLoader April 2021

Medium Eli Salem GuLoader April 2021

Salem, E. (2021, April 19). Dancing With Shellcodes: Cracking the latest version of Guloader. Retrieved July 7, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1055
Process Injection
MalwareGuLoader

GuLoader has the ability to inject shellcode into a donor processes that is started in a suspended state. GuLoader has previously used RegAsm as a donor process.

T1071.001
Web Protocols
MalwareGuLoader

GuLoader can use HTTP to retrieve additional binaries.

T1102
Web Service
MalwareGuLoader

GuLoader has the ability to download malware from Google Drive.

T1105
Ingress Tool Transfer
MalwareGuLoader

GuLoader can download further malware for execution on the victim's machine.

T1106
Native API
MalwareGuLoader

GuLoader can use a number of different APIs for discovery and execution.

T1497.001
System Checks
MalwareGuLoader

GuLoader has the ability to perform anti-VM and anti-sandbox checks using string hashing, the API call EnumWindows, and checking for Qemu guest agent.

T1497.003
Time Based Checks
MalwareGuLoader

GuLoader has the ability to perform anti-debugging based on time checks, API calls, and CPUID.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.