In this twitch stream we take on Guloader. Our approach combines both static and dynamic analysis to bypass the the numerous anti-analysis techniques which make this malware infamous.
The stream goal is not a full analysis of all of the anti-analysis tricks (10 streams later lol) but instead we want to understand enough about the shell code to write our own static config extractor.
14d52119459ef12be3a2f9a3a6578ee3255580f679b1b54de0990b6ba403b0fe
We have decided not to publicly publish this algorithm as the Guloader developers actively monitor and respond to reports on their malware. But we have attached our private notebook with the simple brute force algorithm we developed on stream.