Threat intelligence, Threat Research

SmokeLoader Malware: A Modular Threat with Advanced Evasion and Persistence

by Security News

This week, the SonicWall Capture Labs Threat Research Team reviewed a sample of SmokeLoader malware. This is a modular program used by a variety of criminal and APT groups to gain a foothold on a system. It has vigorous anti-VM, anti-AV, and anti-analysis checks and capabilities. SmokeLoader can be used with RATs, ransomware, backdoors or botnets and uses both file and fileless methods of persistence.

Technical Overview

The main executable is a packed and modified .NET file.

Figure 1: Initial file detection
Figure 1: Initial file detection

The main file looks relatively harmless, with the vast majority of strings and functions in Polish, and relating to Google login prompts with GUI items. There is also a block of seemingly obfuscated text.

Figure 2: File details in dnSpy
Figure 2: File details in dnSpy
Figure 3: Possible obfuscation
Figure 3: Possible obfuscation

At runtime, the main executable will run a series of checks against the host system to verify that the environment is correct and not virtualized. The most notable of which is:

  • A SCSI enumeration via registry key ‘HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSI’
  • Checks the kernel code integrity via NtQuerySystemInformation/CodeIntegrityInformation API calls
  • Uses DebugPort, IsDebuggerPresent, GetTickCount, a custom stack and heap, and dynamic API calls
Figure 4: Anti-VM strings
Figure 4: Anti-VM strings

Once the file determines it can run, it deletes the downloaded data and injects itself into explorer.exe, where it runs further enumeration on the system. Dynamic decryption for C2 addresses occurs after the second stage payload is dropped.

Figure 5: Second stage payload
Figure 5: Second stage payload
Figure 6: Multiple functions have junk code
Figure 6: Multiple functions have junk code

The dropped file is written to ‘C:\Users\User\AppData\Roaming’ and is launched via explorer.exe. This dropped executable then changes file permissions from read-only to executable/writable. Stage two then injects itself into explorer.exe while the parent deletes itself from disk. This is for persistence as well as to use the legitimate process for additional malicious actions.

The C2 addresses decoded in memory are:

  • https://cinems.club/search.php
  • https://clothes.surf/search.php
  • 3.250.92.156:443
  • 172.233.212.90:443

During testing, multiple POST messages were sent to the C2 addresses, but no additional data was downloaded or retrieved.

Sonicwall Protection

SonicWall Capture Labs protects against this threat via the following signature:

  • GAV: Smokeloader.IM (Trojan)

This threat is also detected by SonicWall Capture ATP with RTDMI™, SonicWall Endpoint Security, and the Capture Client endpoint solution.

IOCs

acdad00a1993a10b1cd2377d1da8aecc15ba501e54894efee37275dd2782d4a9

C5aaeee8e7a68fedb5b37300698ef67c30d06a6cf49e7559c1e01520aba26b58

Share This Article

An Article By

Security News

The SonicWall Capture Labs Threat Research Team gathers, analyzes and vets cross-vector threat information from the SonicWall Capture Threat network, consisting of global devices and resources, including more than 1 million security sensors in nearly 200 countries and territories. The research team identifies, analyzes, and mitigates critical vulnerabilities and malware daily through in-depth research, which drives protection for all SonicWall customers. In addition to safeguarding networks globally, the research team supports the larger threat intelligence community by releasing weekly deep technical analyses of the most critical threats to small businesses, providing critical knowledge that defenders need to protect their networks.

Related Articles

  • Neueste Bedrohungsdaten zeigen zunehmende Verbreitung von Cryptojacking
    Read More
  • Die neuesten Bedrohungsdaten geben Einblick in die veränderten Cyberfronten 2022
    Read More
  • Bedrohungsinformationen zur ersten Jahreshälfte 2022: geopolitische Entwicklungen verschieben Grenzen in der Cyberbedrohungslandschaft
    Read More