Dissecting Smoke Loader
ID: b25cc9e3-7576-5fc7-a0a7-07f642124cd7
STIX ID: report--b25cc9e3-7576-5fc7-a0a7-07f642124cd7
Feed Name: CERT Polska
Threat Score
This report dissects the Smoke Loader (Dofoil) malware, showing its layered unpacking, anti-analysis and anti-VM checks, custom import resolution, RC4 and XOR string/encryption routines, propagation/injection methods (including PROPagate), C2 packet formats and algorithms, and practical IOCs (file paths, startup persistence, registry checks, and HTTP request patterns) observed in active RigEK and malspam campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
