The organizers of a hacking competition do not often get to hand their contestants a piece of genuine malware. Insomni’Hack 2025 did. Its GuLosity challenge was built from a real incident-response case — a DFIR case, in the trade’s shorthand — from January 2024, and a newly published writeup walks through how it was meant to be solved.
Safety came first, by subtraction. The specimen was the execution chain of GuLoader, a reflective shellcode loader whose original payload delivered the Remcos remote-access trojan along with an additional keylogger; for the competition, those shellcodes were replaced with benign ones, so participants could dissect the binary without risk while facing the most realistic challenge possible. The object of the exercise was to take the trap apart until the whole chain was understood. Four teams managed it.
There were two roads to that understanding. The easy one is simply to run the sample and watch: Process Monitor quickly spots the light on a PowerShell execution launched from the SysWOW64 directory — 32-bit, in other words — with its window style set to hidden. For all the binary’s magic, that is where the rabbit hole ends.
The command itself is a small study in misdirection. It reads a file buried in a long path of invented names — opslagsvrkerne, incorporative, lathis, Samariterkursussets, Chemosurgical207 — ending in a file called Stippled.leg; it cuts a substring of exactly three characters starting at position 50386 in that file; and it then uses those three characters as the instruction that runs the file’s own contents, the invocation carried out by a bare dot sitting in the string.
The hard road is for the more curious. Under the lens of PEiD and PeStudio, the binary identifies itself as a Nullsoft installer, and an NSIS package can be opened much like a ZIP file by any decompression tool that still supports the format — 7-Zip version 15.05 among them, support having been given up as of version 15.06. Inside sits the installer’s own script, a [NSIS].nsi file, obfuscated; the writeup reproduces it with a few added comments to clarify its internals.
Two routes, then, to the same room: minutes with a process monitor, or an hour unpacking an installer and unweaving its script. Either way the exercise ends where the original case once began, with a loader — this one disarmed so that it could be understood. Four teams made it all the way through; for everyone else, the writeup now serves as the map.

