Hash / BilgiDeger
SHA256654a4d8ff592e34d09c44e6c0d95f9a93bb6361a9c9e069ada5815dd922990bb
MD553b3ecc96a74a90024c3ad375d68558f
SHA137234435d7e0612e030e15938c45a97c8fa21e80
Dosya AdiSETUP.zip
Dosya Türüzip
Boyut3,567,189 bytes
Ilk Görülme2025-09-08

Tehdit Degerlendirmesi

Bu ornek, hedef sisteme ek zararlı yazılım yuklemek amacıyla tasarlanmis moduler bir yukleyici (loader) olarak tespit edilmistir. Bankacılık trojanları, fidye yazılımları veya diger ikinci asama yukler indirebilmektedir.

Tespit Edilen Yetenekler

  • Payload Indirme
  • Surec Enjeksiyonu
  • Kalicilik
  • Anti-Analiz
  • Sifrelenmis Iletisim

MalwareBazaar Etiketleri

file-pumpedRhadamanthysRustyStealerSmokeLoaderzip

Analiz Notu

Bu ornek SmokeLoader ailesine ait ve MalwareBazaar platformundan alınmıstır. KEYDAL Guvenlik Arastirmaları tarafından metadata analizi gerceklestirilmis ve IOC veritabanına eklenmistir.

SmokeLoader — Malware Profile

SmokeLoader. autoruns.exe Sysinternals version info spoofing. Spaso developer PDB username. stub.pdb loader project artifact.

Malware Type
Loader
Programming Language
C
C2 Protocol
HTTP
Target Systems
Windows
Also Known As (AKA)
Dofoil

Technical Details

SmokeLoader (Dofoil/Smoke Bot) is a modular loader/downloader active since 2011. Primary function: download and execute additional payloads (Emotet, TrickBot, FormBook, Ursnif). Heavy obfuscation: string encryption (RC4+XOR), process injection via APC, code injection. Heaven's Gate technique: switches from 32-bit to 64-bit mode to evade WoW64 hooks. Anti-analysis: CPUID-based VM detection, process listing for analysis tools, timing checks. Uses process hollowing to inject into explorer.exe or svchost.exe. C2 communication: RC4-encrypted HTTP POST requests with bot ID, campaign ID. Sold as pay-per-install (PPI) service on underground forums (~$400/1000 installs). Frequently updated to bypass detection, >100 variants documented.

Attribution / Threat Actor

Unknown (sold on underground forums, multiple operators)

Capabilities & Behavior

Payload İndirme
Süreç Enjeksiyonu
Modüler Mimari
Kimlik Bilgisi Hırsızlığı
Yanal Hareket
Kalıcılık
Anti-VM/Sandbox
İkincil Payload Dağıtımı

IOC List (2 indicators)

IOC — SmokeLoader
# SHA256 654a4d8ff592e34d09c44e6c0d95f9a93bb6361a9c9e069ada5815dd922990bb # MD5 53b3ecc96a74a90024c3ad375d68558f
TypeValueNote
sha256 654a4d8ff592e34d09c44e6c0d95f9a93bb6361a9c9e069ada5815dd922990bb
md5 53b3ecc96a74a90024c3ad375d68558f

C2 Servers (5 recorded servers for this family)

Address Type Port Protocol Status Country
80.66.75.36 ip 80 HTTP inactive RU
148.72.171.175 ip 80 HTTP inactive US
91.243.44.247 ip 8888 HTTP inactive RU
185.173.35.16 ip 8080 HTTP inactive RU
torcavpcs1.atitech.com domain 443 TCP inactive —

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
file-pumpedRhadamanthysRustyStealerSmokeLoaderzip