The ASEC analysis team has discovered that the GuLoader malware is being distributed to Korean corporate users. GuLoader is a downloader that has been steadily distributed since the past, downloading various malware. The phishing mail being distributed is as follows, and has an HTML file attached.
When the user opens the attached HTML file, a compressed file is downloaded from the URL below.
- Download URL
The compressed file contains an IMG file and the GuLoader malware is inside this IMG file.
GuLoader is disguised as a Word icon and a Null value of about 600MB in size is added to the end of the file.
It is in the same NSIS format as the GuLoader that has been introduced in the ASEC blog in July, but changes have been made to the NSIS script’s features in the GuLoader that is currently being distributed. The previous NSIS Script had some strings with the names of the DLL and API that it calls, while the new NSIS Script had all the relevant strings removed to bypass detection.
The removed strings are encoded in a particular file. Out of the files generated upon execution of the NSIS file, the “Udmeldt.Ext” file is a shellcode to be loaded later, and the “Modig.Sta0” file is encoded with the names of the DLL and API to be called. The following NSIS script shows the process of the strings being decoded.
First, to call API, XOR is performed from the Modig.Sta0 file’s data in 12278(0x2FF6).
The decoded data is as follows, and it calls the API in order.
When the API is called in order, the “Udmeldt.Ext” file’s data in 21200(0x52D0) is loaded onto the allocated memory before being executed. The data loaded at this point performs the actual malicious behavior.
The loaded GuLoader executes a normal process in the “C:\program files\internet explorer\ieinstal.exe” path before injecting malicious data. The injected normal process connects to the URL below and attempts to download additional malware. Download is not available at the current moment, but it can download infostealers and RAT types of malware, including Formbook, RedLine, and AgentTesla.
- Download URL
The downloader malware GuLoader is continuously being modified and distributed to bypass detection. Caution is advised as it is targeting Korean users, and users should not open attachments in emails from unknown sources. AhnLab’s anti-malware product, V3, detects and blocks the malware using the alias below.
Subscribe to AhnLab’s next-generation threat intelligence platform ‘AhnLab TIP’ to check related IOC and detailed analysis information.