ATT&CKReferencesMalwarebytes SmokeLoader 2016

Malwarebytes SmokeLoader 2016

Hasherezade. (2016, September 12). Smoke Loader – downloader with a smokescreen still alive. Retrieved March 20, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareSmoke Loader

Smoke Loader uses a simple one-byte XOR method to obfuscate values in the malware.

T1055.012
Process Hollowing
MalwareSmoke Loader

Smoke Loader spawns a new copy of c:\windows\syswow64\explorer.exe and then replaces the executable code in memory with malware.

T1059.005
Visual Basic
MalwareSmoke Loader

Smoke Loader adds a Visual Basic script in the Startup folder to deploy the payload.

T1071.001
Web Protocols
MalwareSmoke Loader

Smoke Loader uses HTTP for C2.

T1105
Ingress Tool Transfer
MalwareSmoke Loader

Smoke Loader downloads a new version of itself once it has installed. It also downloads additional plugins.

T1547.001
Registry Run Keys / Startup Folder
MalwareSmoke Loader

Smoke Loader adds a Registry Run key for persistence and adds a script in the Startup folder to deploy the payload.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.