MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c7d04743911aa4264b47d44df511d4c1f72dc789293b2457bf995ca2a592add3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Smoke Loader


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: c7d04743911aa4264b47d44df511d4c1f72dc789293b2457bf995ca2a592add3
SHA3-384 hash: eb43a4f750cf11bef6075d8b701736d8fb416c34bbeaa78ef5666247f8277a64d9ef65b1e58d2748bb3c1e980a25f752
SHA1 hash: 76a7deb9b3324c9e16b79d21e2d6f748d42589d0
MD5 hash: 5470bef17dcaeddad800d71b451e20f1
humanhash: bravo-indigo-william-monkey
File name:Договiр_поставки.js
Download: download sample
Signature Smoke Loader
File size:16'967 bytes
First seen:2025-02-01 15:36:06 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 384:o20O2IK22cBlxREsgnoVRlBxBOFtljOxxrg8yJ186CxpjlJxj96lxqctTxlxVlXg:o20O2IK22cBlxREsgnoVRlBxBOFtljOp
Threatray 3'089 similar samples on MalwareBazaar
TLSH T10E726B360A1D065215D7F1C5CCD4D7261BB3E284BF36AE82AA468AD52FF8CC67903C76
Magika javascript
Reporter abuse_ch
Tags:js Smoke Loader

Intelligence


File Origin
# of uploads :
1
# of downloads :
453
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
phishing shell agent sage
Result
Threat name:
SmokeLoader
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Benign windows process drops PE files
C2 URLs / IPs found in malware configuration
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Creates a thread in another existing process (thread injection)
Detected unpacking (changes PE section rights)
Found malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
JScript performs obfuscated calls to suspicious functions
Machine Learning detection for dropped file
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Powershell drops PE file
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Yara detected SmokeLoader
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1604512 Sample: #U0414#U043e#U0433#U043e#U0... Startdate: 01/02/2025 Architecture: WINDOWS Score: 100 53 x1.i.lencr.org 2->53 55 restructurisationservice.ru 2->55 57 5 other IPs or domains 2->57 67 Suricata IDS alerts for network traffic 2->67 69 Found malware configuration 2->69 71 Malicious sample detected (through community Yara rule) 2->71 73 4 other signatures 2->73 10 wscript.exe 1 1 2->10         started        13 jfggvib 2->13         started        15 jfggvib 2->15         started        17 svchost.exe 1 1 2->17         started        signatures3 process4 dnsIp5 85 JScript performs obfuscated calls to suspicious functions 10->85 87 Suspicious powershell command line found 10->87 89 Wscript starts Powershell (via cmd or directly) 10->89 103 2 other signatures 10->103 20 powershell.exe 17 20 10->20         started        91 Multi AV Scanner detection for dropped file 13->91 93 Detected unpacking (changes PE section rights) 13->93 95 Machine Learning detection for dropped file 13->95 105 3 other signatures 13->105 97 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 15->97 99 Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation)) 15->99 101 Maps a DLL or memory area into another process 15->101 51 127.0.0.1 unknown unknown 17->51 signatures6 process7 dnsIp8 59 2.59.163.172, 49731, 80 VMAGE-ASRU Russian Federation 20->59 43 C:\Users\user\AppData\Roaming\svc2.exe, PE32 20->43 dropped 75 Powershell drops PE file 20->75 25 svc2.exe 20->25         started        28 Acrobat.exe 75 20->28         started        30 conhost.exe 20->30         started        file9 signatures10 process11 signatures12 77 Multi AV Scanner detection for dropped file 25->77 79 Detected unpacking (changes PE section rights) 25->79 81 Machine Learning detection for dropped file 25->81 83 5 other signatures 25->83 32 explorer.exe 30 2 25->32 injected 37 AcroCEF.exe 106 28->37         started        process13 dnsIp14 45 restructurisationservice.ru 94.156.177.72, 49752, 49987, 49999 NET1-ASBG Bulgaria 32->45 47 connecticutproperty.ru 88.151.192.71, 49753, 49993, 50005 AZERONLINEAZ Azerbaijan 32->47 41 C:\Users\user\AppData\Roaming\jfggvib, PE32 32->41 dropped 61 System process connects to network (likely due to code injection or exploit) 32->61 63 Benign windows process drops PE files 32->63 65 Hides that the sample has been downloaded from the Internet (zone.identifier) 32->65 49 e8652.dscx.akamaiedge.net 2.19.105.127, 49744, 80 AKAMAI-ASUS European Union 37->49 39 AcroCEF.exe 2 37->39         started        file15 signatures16 process17
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Command and Scripting Interpreter: PowerShell
Checks computer location settings
Executes dropped EXE
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments