Live Stream VOD: SmokeLoader Analysis Part 3 - Stage 3 Decrypted and Config Extracted (Patreon)
Published:
2022-09-03 04:37:38
Imported:
2022-12
Content
The conclusion to our analysis of SmokeLoader! All the secrets are revealed and it's grrr-eat! We finally figure out the missing piece for the API hashes and resolve them. This leads us to the missing piece of the puzzle for extracting Stage 3 - LZSA2 decompression!
Once we have decrypted and decompressed Stage 3 we quickly locate the encrypted strings table, and the encrypted C2 table building ourselves a static config extractor!
This was a pretty triumphant conclusion if I do say so myself : )
Samples
- Packed parent cef4f5f561b5c481c67e0a9a3dd751d18d696b61c7a5dab5ebb29535093741b4
- Unpacked SmokeLoader 041a05dd902a55029449bf412cedbe59a593f8d4e67d4ae37cf7a928c92f22ca