Hasherezade. (2016, September 12). Smoke Loader – downloader with a smokescreen still alive. Retrieved March 20, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareSmoke Loader | Smoke Loader uses a simple one-byte XOR method to obfuscate values in the malware. |
| T1055.012 Process Hollowing |
MalwareSmoke Loader | Smoke Loader spawns a new copy of c:\windows\syswow64\explorer.exe and then replaces the executable code in memory with malware. |
| T1059.005 Visual Basic |
MalwareSmoke Loader | Smoke Loader adds a Visual Basic script in the Startup folder to deploy the payload. |
| T1071.001 Web Protocols |
MalwareSmoke Loader | Smoke Loader uses HTTP for C2. |
| T1105 Ingress Tool Transfer |
MalwareSmoke Loader | Smoke Loader downloads a new version of itself once it has installed. It also downloads additional plugins. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSmoke Loader | Smoke Loader adds a Registry Run key for persistence and adds a script in the Startup folder to deploy the payload. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.