PULSE NAME
Operation Endgame: Up In Smoke
WHITE AlienVault 2024-05-30 Modified: 2024-05-30
12
IOCs
MEDIUM VOLUME
A detailed technical analysis of Smoke malware loader, also known as SmokeLoader or Dofoil, which has been operational since 2011. Smoke is primarily used to deliver second-stage malware payloads like trojans, ransomware, and information stealers, and can also deploy custom plugins for various malicious activities. The analysis covers Smoke's persistence mechanisms, network communication, and remote cleanup process, and how the international law enforcement operation 'Endgame' disrupted its infrastructure and remotely uninstalled the malware.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
SmokeLoader
Indicators of Compromise (12)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain akmedia.in 2024-05-30
domain bethesdaserukam.org 2024-05-30
domain galandskiyher5.com 2024-05-30
domain gxutc2c.com 2024-05-30
domain humman.art 2024-05-30
domain kkudndkwatnfevcaqeefytqnh.top 2024-05-30
domain nidoe.org 2024-05-30
domain servermlogs27.xyz 2024-05-30
domain trad-einmyus.com 2024-05-30
domain trybobry.com.ua 2024-05-30
domain vacantion18ffeu.cc 2024-05-30
domain whxzqkbbtzvdyxdeseoiyujzs.co 2024-05-30