Smoke Loader poses as an Office plugin
ID: 9a2b10fd-cde9-566d-828e-ee0315fc4daa
STIX ID: report--9a2b10fd-cde9-566d-828e-ee0315fc4daa
Feed Name: CERT Polska
This report describes a targeted Smoke Loader malware campaign against Polish users that used a fake Microsoft Office browser-plugin installer to drop a Visual Basic-packed payload (DONEAPP.EXE). The loader establishes persistence in %APPDATA%, tests connectivity via msn.com, contacts an encrypted C2 (cannedgood.eu), and supports plugins including Rootkit.dll (hooks NtEnumerateValueKey and NtQueryDirectoryFile to hide autorun registry keys and files) and Faker.dll (intercepts and alters DNS responses), enabling stealthy data-collection and redirection for phishing; the infrastructure was quickly abandoned after publicity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
