216.73.216.233

SmokeBuster Tool

· Published 31/10/2024 21:16 · Modified 05/11/2024 10:03

Export JSON

Essential information

Published
31/10/2024 21:16
Modified
05/11/2024 10:03
Tags
2024-10-31 dofoil malware analysis memory injection operation endgame smokebuster smokeloader system performance thread manipulation windows
Related entities
10 techniques (mitre), 3 malware

Description

ThreatLabz has developed , a tool to detect, analyze, and remove malware from infected systems. Despite 's disruption in May 2024, continues to be used by threat groups. supports various versions and systems, offering features like uninstallation, thread control, and memory manipulation. The tool revealed bugs in recent versions that significantly degrade . These flaws stem from persistence implementation, infection checks, and inadequate thread and memory cleanup. The bugs cause repeated injections and thread creation, leading to system slowdown over time. 's capabilities may accelerate 's decline, especially given its performance-degrading flaws.

External references