Smokeloader is a small modular bot first seen in 2011 [1] mainly used as a dropper for other malware families. Although mainly used for delivering a second stage stage, Smokeloader implements several malicious capabilities through its modules, such as: keylogging, process monitoring, DDOS, DNS redirection and form grabbing. These modules are often used for profiling and accessing infected machines before deploying a final malware increasing effectiveness of campaigns.
- So here comes the main story -
Last week I saw a tweet [2] with an image of this server hosting few quite large executables (~1.2MB) claimed to be Smokeloader samples. These binaries were accessible through an Open Directory.
![]() |
| Figure 01: Open Directory exposing modified Smokeloader samples. |
Along the 30th and 31st of July these files were changed few times. Here are the hashes found and analysed during the time of this research:
- 6632e26a6970d8269a9d36594c07bc87d266d898bc7f99198ed081d9ff183b3f joibr.exe
- 1cea3a87500fdc933aa64cc45373034b1da6921644640106cd56483aa758b3bf jony.exe
- 501675053b0d4ba02477900a5b28829e2f009f68dffc044d51ba3d2c61c042b9 ktmy.exe
- 8d40fb9983050026c86277d9443d384e1a1aee92582cc2e61415fa6a3a0b4c99 ktzb.exe
- 065871459fa254daa362564b70ea4357bb197ef04cfee8de7426cfdf480e4a78 smbn.exe
