In this twitch stream we take another look at Guloader's VEH obfuscation using Dumpulator. With Dumpulator we are able to bypass the obfuscation to extract the encrypted strings, as well as create a simple instruction color trace in IDA to identify the program flow.
E3A8356689B97653261EA6B75CA911BC65F523025F15649E87B1AEF0071AE107
m4n0w4r
2023-08-09 07:48:50 +0000 UTCm4n0w4r
2023-07-29 14:49:38 +0000 UTCm4n0w4r
2023-07-29 05:05:15 +0000 UTCOALABS
2023-07-29 04:11:27 +0000 UTCm4n0w4r
2023-07-29 04:09:08 +0000 UTC