Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
46
Global rank
72 infographic chevron month
Month rank
102 infographic chevron week
Week rank
0
IOCs

The main function of Smoke Loader is dropping other, more destructive malware on infected machines. However, unlike many competing loaders, this one can be extended via plugins to feature destructive, malicious info-stealing functions.

Loader
Type
ex-USSR territory
Origin
30 August, 2011
First seen
26 August, 2026
Last seen
Also known as
Dofoil

How to analyze Smoke Loader with ANY.RUN

Type
ex-USSR territory
Origin
30 August, 2011
First seen
26 August, 2026
Last seen

IOCs

IP addresses
103.54.153.49
63.40.139.116
202.95.11.181
185.199.110.133
204.242.111.216
140.82.121.4
76.181.127.0
64.89.163.22
88.178.85.213
62.50.124.173
73.178.125.121
178.198.226.213
196.251.107.186
172.245.95.62
85.137.245.141
161.171.54.201
187.208.110.213
157.173.29.19
85.186.8.75
122.42.218.141
Hashes
92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50
d3acd72f585872f36d7329faf6146dc2d71c3cbcbd58d94e36da285738adaa68
e728f79439e07df1afbcf03e8788fa0b8b08cf459db31fc8568bc511bf799537
7f0121322785c107bfdfe343e49f06c604c719baff849d07b6e099675d173961
aac73b3148f6d1d7111dbca32099f68d26c644c6813ae1e4f05f6579aa2663fe
5822c2222c4a4121a1667c7d483ff8b91e489a4c5e881c75a4354712bfe6f435
26b4699a7b9eeb16e76305d843d4ab05e94d43f3201436927e13b3ebafa90739
15ffbb8d382cd2ff7b0bd4c87a7c0bffd1541c2fe86865af445123bc0b770d13
14dec7d1c20fc426ad5463d1b658f87a22f7e576ba4a08905caf399551813a72
2d79af8e1ff3465703e1dc73d3ef2182fd269ea2609c8afabdf1b80693405c1d
d30d7676a3b4c91b77d403f81748ebf6b8824749db5f860e114a8a204bca5b8f
96425ae53a5517b9f47e30f6b41fdc883831039e1faba02fe28b2d5f3efcdc29
4ae7d63ec497143c2acde1ba79f1d9eed80086a420b6f0a07b1e2917da0a6c74
b5fc4fd50e4ba69f0c8c8e5c402813c107c605cab659960ac31b3c8356c4e0ec
db0c7e3029fb2a048e7a3e74c9cbf3e8bcec06288b5eafac5aae678d8663bffc
3e59379f585ebf0becb6b4e06d0fbbf806de28a4bb256e837b4555f1b4245571
fc103a323d70caaac475ae1cfcacfd8eec4c6b1e130005c4793f2013b4b019f8
031ed0378f819926d7b5b2c6c9367a0fb1cbae40e1a3959e2652fe30a47d52f2
27f13c4829994b214bb1a26eef474da67c521fd429536cb8421ba2f7c3e02b5f
45791627ae8e67e6b616117cf21f04da381722faf08d07c0c25e0f28c9b8f82b
Domains
fkoqonr2vgbsw7qu.public.blob.vercel-storage.com
dl.natgo.cn
www.benshamcentre.co.uk
1h.vuregyy1.ru
tmcksa.com
cat.dashabi.in
c3436037.salamanderprocessing.pages.dev
vizyonuniversitesi.com.tr
hnjgdl.geps.glodon.com
palharesinformatica.com.br
www.astenterprises.com.pk
imagefiles-backup.oss-ap-southeast-7.aliyuncs.com
practisingcertificateprotection.com
konsor.ru
dcwblida.dz
www.hwgeneralins.com
www.saf-oil.ru
99194034-96-20180108171507.webstarterz.com
www.microsoft.com
local-update.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://45.13.186.37/crypt/21-32/qw1.exe
http://196.251.107.186/clpr11.exe
http://196.251.107.186/asemkiic.exe
http://193.104.58.65/binyu.exe
http://91.92.242.236/files-129312398/files/file_b41995cf38e90365.exe
http://91.92.242.236/files-129312398/files/file_6bbb893ae4adfb7c.exe
http://217.60.195.219/boss/boss.bat
http://196.251.107.186/clpmem.exe
http://85.203.4.64/notepad.exe
http://193.221.200.26:5001/odens.exe
http://217.60.195.219/ty/s.bat
http://85.203.4.64/client.exe
http://91.92.242.236/files-129312398/files/file_a91ac6d4a7389993.exe
http://91.92.242.236/files-129312398/files/file_21aeb275da3bb00b.exe
http://91.92.242.236/files-129312398/files/file_44ef7cc8421220d0.exe
http://196.251.107.186/uniform_4.44_install.exe
http://196.251.107.186/clp4.exe
http://196.251.107.186/2.7.exe
http://178.16.54.109/getit.exe
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2800
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7890
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10855
comments 0

What is Smoke Loader?

Smoke Loader, sometimes also called Dofoil, is a modular malware mainly utilized to download other viruses to infected machines. Despite its loader nature, the Smoke Loader bot can be equipped with a variety of malicious functions. Most of these functions are targeted at stealing sensitive data from the victims.

Smoke Loader was first observed in the wild in 2011. It was seen being sold on underground portals grabberz[.]com and xaker[.]name by a member named SmokeLdr. The malware functionality varies from one attack to the other and depends on the choice of modules done by the attackers.

Despite its old age, Smoke Loader continues to be an active threat even to this day. In particular, this malware was featured in RigEK and MalSpam campaigns. It should be noted that after March 2014, Smoke Loader is sold only to Russian-speaking attackers.

General description of Smoke Loader

The main functions of Smoke Loader include loading up to ten executable files and run them, geo-target the victims to direct attacks at specific countries, load files via URLs, mimic legitimate processes, and provide detailed summaries on installs and launches.

The two optional modules allow Smoke Loader to expand its feature set with information-stealing functions. This allows Dofoil to grab passwords from widely used mail clients, FTP clients, and programs like TeamViewer. The malware can send the data to the C2 for the attacker.

The Smoke Loader virus has been evolving over the years. According to the research of a cybersecurity professional, a late 2018 sample included an array of anti-debugging techniques far more complex than anything present in the early iterations of the malware. For instance, the 2018 Smoke Loader version learned to check if it is being launched in the virtual environment. It also learned to discover and immediately kill any analyzing tools running on the machine. Together, these features make the analysis of the Dofoil malware highly complicated. Dofoil also relies a lot on the process hollowing technique, targeting mostly Explorer.exe.

What’s more, while a lot of malware in the wild need to iterate through a list of processes to find their injection target, thus allowing researchers to discover them, Smoke Loader manages to avoid this behavior and stay hidden by calling the Windows API GetShellWindow to access the shell’s desktop window, and evoke GetWindowThreadProcessId to obtain the process ID of Explorer.exe.

To further confuse security researchers, all Smoke Loader functions contain pointless instructions. At the same time, the library names are encrypted with a hardcoded key. Instructions are not coded in a standard way. Instead, they are mixed with jump instructions. Most of this code reroutes the program flow to create confusion when Dofoil is debugged.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Malware analysis of Smoke Loader

A video recorded in the ANY.RUN malware hunting service displays the execution process of Smoke Loader. It allows examining the malware in a convenient and safe environment.

smokeloader execution process graph

Figure 1: Displays the graph of processes generated by the ANY.RUN malware analyzing service

text report of the smokeloader malware analysis

Figure 2: Even more information about the execution of malware can be found in customizable text reports generated by ANY.RUN

Smoke Loader execution process

So, how does Smoke Loader work? Because the most common vector of attack to infect users' devices are malicious spam campaigns, Smoke Loader trojan mostly gets into devices with Microsoft Office files. Once the user downloads and opens the malicious file, the malware drops to a machine from it.

After that, SmokeLoader injects malicious code into system processes like explorer.exe. An injected process then starts the main malicious activity.

Distribution of Smoke Loader

The smoke Loader virus makes its way to machines as a malicious Microsoft Word attachment. It is initially delivered to users in spam email campaigns. Attackers use social engineering to trick potential victims into downloading the attached file and enabling the macros, the same scenario is applied by Ave Maria and Revenge.

This makes contamination prevention fairly simple. Users are advised to stay clear of downloading files from suspicious emails and keep macros disabled. And especially, never enable them if prompted by a downloaded file.

How Smoke Loader communicates with C&C?

Smoke Loader malware tries to hide its malicious nature. This is done by mixing infrequent requests to legitimate websites into C&C communication. The virus connects to websites such as Microsoft.com and Adobe.com. Despite receiving mainly HTTP 404 in requests, data is still evident in the response body.

How to detect Smoke Loader using ANY.RUN?

Since SmokeLoader almost always infects systems using similar attack vectors, it can be identified using its execution process. After the executable file, which contains Smoke Loader, has been delivered in the system and launched, it injects its code into the system process like "explorer.exe."

This means that if, after some time following the execution of a sample, an "explorer.exe" process appears, it is time to look into it. To do so, click on the process in the "Process list" section, and in the appeared "Process details" window click the "More info" button. If in the event section you see that previously injected "explorer.exe" create a file named "tesrdgeh.exe," it is a clear indication that you are dealing with Smoke Loader trojan.

SmokeLoader created a file Figure 3: Injected explorer.exe created file tesrdgeh.exe

Summary

Despite being rather old, the Dofoil virus is only gaining popularity. Since its first surfacing in 2011, the malware remains a highly active and elusive threat, not due to its advanced anti-evasion functions. In addition to being used as a loader and installing potentially more dangerous malware.

What’s more, Smoke Loader itself can be used to pull sensitive information from infected machines and conduct destructive, malicious campaigns.

Thankfully, advanced malware hunting services such as ANY.RUN allows us to bypass some of the anti-evasion tricks implemented by the Smoke Loader creators and successfully conduct the analysis of this virus.

HAVE A LOOK AT

BlindEagle screenshot
BlindEagle
blindeagle
BlindEagle is a cyber threat actor primarily associated with espionage and credential theft campaigns targeting organizations in Latin America, especially Colombia. Active since at least 2018, the group relies heavily on phishing, remote access trojans (RATs), PowerShell scripts, and social engineering to infiltrate systems and maintain persistence. BlindEagle is known for continuously evolving its delivery mechanisms and malware stack to bypass detection and compromise high-value targets.
Read More
Moonrise screenshot
Moonrise
moonrise
Moonrise RAT is a newly discovered Go-based remote access trojan with zero detections at launch, featuring credential theft, keylogging, webcam access, clipboard hijacking, and UAC bypass.
Read More
Pay2Key screenshot
Pay2Key is a ransomware strain primarily written in C++ for Windows (with recent Linux variants), attributed to Iranian-linked actors, notably the Fox Kitten APT group (also known as UNC757 or related operations). First observed in late 2020, it employs double-extortion tactics (encrypting files and threatening to leak stolen data) while showing signs of both financial and state-aligned motivations. It has resurfaced in campaigns targeting Western organizations, including rapid encryption attacks on healthcare.
Read More
PureCrypter screenshot
PureCrypter
purecrypter
First identified in March 2021, PureCrypter is a .NET-based loader that employs obfuscation techniques, such as SmartAssembly, to evade detection. It has been used to distribute malware families including AgentTesla, RedLine Stealer, and SnakeKeylogger. The malware is typically delivered through phishing campaigns and malicious downloads, often masquerading as legitimate files with extensions like .mp4 or .pdf. PureCrypter utilizes encryption and compression to conceal its payloads and can inject malicious code into legitimate processes to maintain persistence on the infected system.
Read More
WhiteSnake screenshot
WhiteSnake
whitesnake
WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.
Read More
StrelaStealer screenshot
StrelaStealer
strela
StrelaStealer is a malware that targets email clients to steal login credentials, sending them back to the attacker’s command-and-control server. Since its emergence in 2022, it has been involved in numerous large-scale email campaigns, primarily affecting organizations in the EU and U.S. The malware’s tactics continue to evolve, with attackers frequently changing attachment file formats and updating the DLL payload to evade detection.
Read More