MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 62fa2bb550dc64e7768fc2da9954182675ae3675c008daba18e0fe4a4b7af1de. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Smoke Loader


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: 62fa2bb550dc64e7768fc2da9954182675ae3675c008daba18e0fe4a4b7af1de
SHA3-384 hash: 9e0d6e432de53e667bcd2be0a7dd74403789bc437fe90e20cc2849452c6a38642e5dd58c10f92b1c2c402bf4bf2c2234
SHA1 hash: 34b15a1a3f9c6c4c050d9ed636007924f173379f
MD5 hash: 87c01edf054abfc30aa9b3328d92e1c7
humanhash: arkansas-batman-december-gee
File name:ORDER-11.zip
Download: download sample
Signature Smoke Loader
File size:252'421 bytes
First seen:2023-06-14 07:34:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:dJYeWP9ABZj0EesS0G2ANfJZVNwzK7WVOztJ054rg2yAI:d6HEeJ9DVNqUWKDJrdyp
TLSH T15B34236033205C91F586797868154EF6CEDA4B296CDE0871F9F29001AD6CF0B939BB3B
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter cocaman
Tags:Smoke Loader zip


Avatar
cocaman
Malicious email (T1566.001)
From: "Ahmed MORSY <owgq@mail.notes.bank-of-china.com>" (likely spoofed)
Received: "from hwsrv-1074756.hostwindsdns.com (hwsrv-1074756.hostwindsdns.com [104.168.169.51]) "
Date: "13 Jun 2023 12:18:11 +0000"
Subject: "FW: RE: NEW ORDER"
Attachment: "ORDER-11.zip"

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
CH CH
File Archive Information

This file archive contains 7 file(s), sorted by their relevance:

File name:view-mirror-symbolic.svg
File size:1'726 bytes
SHA256 hash: ffce3cd4069d4559b0bdd8b990f8ce3f1270de831c72e64508e8ec3dad588411
MD5 hash: bd526c38c3464d62335d3a11af60c0c1
MIME type:image/svg+xml
Signature Smoke Loader
File name:System.dll
File size:11'776 bytes
SHA256 hash: 6fcea34c8666b06368379c6c402b5321202c11b00889401c743fb96c516c679e
MD5 hash: fccff8cb7a1067e23fd2e2b63971a8e1
MIME type:application/x-dosexec
Signature Smoke Loader
File name:system-help-symbolic.svg
File size:1'761 bytes
SHA256 hash: 61b2200490495b88963845f73e131455f43426d5f814d7b69e6ba414a17c2cfa
MD5 hash: cb3c86675aac6c157ff384b723d3b430
MIME type:image/svg+xml
Signature Smoke Loader
File name:selection-start-symbolic.symbolic.png
File size:142 bytes
SHA256 hash: ab86f801b5ed71c581e2a68b6e052953c6b5b95dfbc617a117dea9b084429618
MD5 hash: b361cad290962835529009e96e49cc9f
MIME type:image/png
Signature Smoke Loader
File name:Tilskdningernes.Lan
File size:257'965 bytes
SHA256 hash: 3d79d9cd2c3d69df96b09bfce7b3f4f0f549c5934b60337af8e6d65358601a31
MD5 hash: 1d65d1ff851636273a6dc87531e91a1c
MIME type:application/octet-stream
Signature Smoke Loader
File name:shortcuts.xml
File size:1'581 bytes
SHA256 hash: 6fca9f75d7178daec64638a3294c478651b9f9286a9d8a368bc70bcedd19b8fd
MD5 hash: ced25ee505bcdbb49617cfd06e892d25
MIME type:text/plain
Signature Smoke Loader
File name:ORDER-11028874..pif
File size:328'952 bytes
SHA256 hash: eb70d795a9bc30cd25af85d26eeb6807375dcbb5ea1cd3648df10dcd7f6f717d
MD5 hash: 22b52826983dda65910e1d97a1c2958f
MIME type:application/x-dosexec
Signature Smoke Loader
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
buer lolbin overlay packed shell32.dll
Threat name:
Win32.Trojan.Guloader
Status:
Malicious
First seen:
2023-06-13 11:06:51 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
smokeloader
Score:
  10/10
Tags:
family:guloader family:smokeloader backdoor downloader trojan
Behaviour
Checks SCSI registry key(s)
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
Drops file in Windows directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Checks QEMU agent file
Loads dropped DLL
Guloader,Cloudeye
SmokeLoader
Malware Config
C2 Extraction:
http://zasicath.com/
http://etasicath.com/
http://pyasicath.com/
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:QbotStuff
Author:anonymous

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Smoke Loader

zip 62fa2bb550dc64e7768fc2da9954182675ae3675c008daba18e0fe4a4b7af1de

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments