Smoke Loader is used to infect with team viewer rat 4.34-2mb size of executable.
Domains :
bookwormsbiorhythm.top
charlesadvanced.top
Ip’s :
185.81.113.86:80
200.7.98.161:80
104.16.41.2:443
217.23.11.14:80
23.51.123.27:80
92.122.201.2:443
92.122.122.136:80
Samples :
hxxp://185.81.113.106/ital2.exe
hxxp://200.7.105.4/ital1.exe
hxxp://200.7.98.161/myonly3d.exe
hxxp://theplatonicsolid.com/cftmon.exe
hxxp://memorywedge.net/11/cftmon.exe
hxp://memorywedge.net/11/1.zip :
The whole archive(shells,emailer,samples), his gmail adress to.This guy looks like big russki hecker.