Salem, E. (2021, April 19). Dancing With Shellcodes: Cracking the latest version of Guloader. Retrieved July 7, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
MalwareGuLoader | GuLoader has the ability to inject shellcode into a donor processes that is started in a suspended state. GuLoader has previously used RegAsm as a donor process. |
| T1071.001 Web Protocols |
MalwareGuLoader | GuLoader can use HTTP to retrieve additional binaries. |
| T1102 Web Service |
MalwareGuLoader | GuLoader has the ability to download malware from Google Drive. |
| T1105 Ingress Tool Transfer |
MalwareGuLoader | GuLoader can download further malware for execution on the victim's machine. |
| T1106 Native API |
MalwareGuLoader | GuLoader can use a number of different APIs for discovery and execution. |
| T1497.001 System Checks |
MalwareGuLoader | GuLoader has the ability to perform anti-VM and anti-sandbox checks using string hashing, the API call |
| T1497.003 Time Based Checks |
MalwareGuLoader | GuLoader has the ability to perform anti-debugging based on time checks, API calls, and CPUID. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.