
This week, the SonicWall Capture Labs Threat Research Team reviewed a sample of SmokeLoader malware. This is a modular program used by a variety of criminal and APT groups to gain a foothold on a system. It has vigorous anti-VM, anti-AV, and anti-analysis checks and capabilities. SmokeLoader can be used with RATs, ransomware, backdoors or botnets and uses both file and fileless methods of persistence.
The main executable is a packed and modified .NET file.

The main file looks relatively harmless, with the vast majority of strings and functions in Polish, and relating to Google login prompts with GUI items. There is also a block of seemingly obfuscated text.


At runtime, the main executable will run a series of checks against the host system to verify that the environment is correct and not virtualized. The most notable of which is:

Once the file determines it can run, it deletes the downloaded data and injects itself into explorer.exe, where it runs further enumeration on the system. Dynamic decryption for C2 addresses occurs after the second stage payload is dropped.


The dropped file is written to ‘C:\Users\User\AppData\Roaming’ and is launched via explorer.exe. This dropped executable then changes file permissions from read-only to executable/writable. Stage two then injects itself into explorer.exe while the parent deletes itself from disk. This is for persistence as well as to use the legitimate process for additional malicious actions.
The C2 addresses decoded in memory are:
During testing, multiple POST messages were sent to the C2 addresses, but no additional data was downloaded or retrieved.
SonicWall Capture Labs protects against this threat via the following signature:
This threat is also detected by SonicWall Capture ATP with RTDMI™, SonicWall Endpoint Security, and the Capture Client endpoint solution.
acdad00a1993a10b1cd2377d1da8aecc15ba501e54894efee37275dd2782d4a9
C5aaeee8e7a68fedb5b37300698ef67c30d06a6cf49e7559c1e01520aba26b58
Share This Article

An Article By
An Article By
Security News
Security News
