Malware Analysis - Fileless GooLoad static analysis and unpacking

Опубликовано: 22 Апрель 2026
на канале: MalwareAnalysisForHedgehogs
3,151
102

GooLoad is delivered via SEO poisoning of malicious websites and delivered as JScript in a ZIP archive, often disguised as important document. After installation it works as a fileless loader for the payload which can be Gozi, Gootkit, Kronos or Remcos. GooLoad uses the registry to reside in and inject the payload into legitimate processes. We analyze a GooLoad sample and statically unpack the various stages of the infection chain.


Note: I named the sample Gozi in the video. This is wrong identification/mix up with the payload!

Malware analysis courses: https://malwareanalysis-for-hedgehogs...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter:   / struppigel  

Download sample: https://bazaar.abuse.ch/sample/6bb71d...
Referenced tweet:   / 1349711868240289792  

Process injection infographic: http://struppigel.blogspot.com/2017/0...

Used tools:
de4js: https://lelinhtinh.github.io/de4js/
DnSpy: https://github.com/dnSpy/dnSpy/releases
PEStudio: https://www.winitor.com/
Notepad++: https://notepad-plus-plus.org/downloads/
Python: https://www.python.org/downloads/
Sysinternals: https://docs.microsoft.com/en-us/sysi...