GooLoad is delivered via SEO poisoning of malicious websites and delivered as JScript in a ZIP archive, often disguised as important document. After installation it works as a fileless loader for the payload which can be Gozi, Gootkit, Kronos or Remcos. GooLoad uses the registry to reside in and inject the payload into legitimate processes. We analyze a GooLoad sample and statically unpack the various stages of the infection chain.
Note: I named the sample Gozi in the video. This is wrong identification/mix up with the payload!
Malware analysis courses: https://malwareanalysis-for-hedgehogs...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter: / struppigel
Download sample: https://bazaar.abuse.ch/sample/6bb71d...
Referenced tweet: / 1349711868240289792
Process injection infographic: http://struppigel.blogspot.com/2017/0...
Used tools:
de4js: https://lelinhtinh.github.io/de4js/
DnSpy: https://github.com/dnSpy/dnSpy/releases
PEStudio: https://www.winitor.com/
Notepad++: https://notepad-plus-plus.org/downloads/
Python: https://www.python.org/downloads/
Sysinternals: https://docs.microsoft.com/en-us/sysi...