PULSE NAME
Sakula Reloaded
WHITE AlienVault 2015-11-18 Modified: 2017-07-25
23
IOCs
MEDIUM VOLUME
Sakula is a well known malware variant linked to several significant targeted intrusion campaigns over the past 2-3 years. This remote access toolkit has been publicly examined multiple times by the threat intelligence community. CrowdStrike has released two blog posts detailing Sakula campaigns and continues to investigate its usage. In the past two years, two campaigns of Sakula activity stand out as being particularly significant – the “French Aerospace” Campaign and the “Ironman” Campaign. In recent months, CrowdStrike has observed limited use of what appears to be a third Sakula variant.
Indicators of Compromise (23)
All domain URL hostname CVE YARA FileHash-SHA256 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
domain inocnation.com 2015-11-18
domain we11point.com 2015-11-18
URL http://www.cbppnews.com/movie.swf 2015-11-18
hostname cdn.sanecat.com 2015-11-18
hostname oa.ameteksen.com 2015-11-18
hostname capstone.homeftp.net 2015-11-18
hostname webmail.vipreclod.com 2015-11-18
CVE CVE-2015-5119 2015-11-18
CVE CVE-2014-0322 2015-11-18
YARA ae7f60ede2f4ad6567224efc2d2b10cb685530d2 2017-07-24
YARA 13518b0620a55bc2a4b97ec9a07fa7acc09d9560 2017-07-24
YARA 130ce7146596c5896cc060510bec2c2d2a4dfdfa 2017-07-24
YARA a72bbda5b897993d87dfa427740ffa5945ba61b3 2017-07-24
FileHash-SHA256 ab58b6aa7dcc25d8f6e4b70a24e0ccede0d5f6129df02a9e61293c1d7d7640a2 2017-07-24
FileHash-SHA256 c6c3bb72896f8f0b9a5351614fd94e889864cf924b40a318c79560bbbcfa372f 2017-07-24
FileHash-SHA1 38e21f0b87b3052b536408fdf59185f8b3d210b9 2017-07-24
FileHash-SHA1 5d201a0fb0f4a96cefc5f73effb61acff9c818e1 2017-07-24
FileHash-SHA1 ffb1d8ea3039d3d5eb7196d27f5450cac0ea4f34 2017-07-24
YARA 9c797c5fa4e142124fa2196019015698801de1ba 2017-07-25
YARA b5722256e2ce4af26e62eb111a158418aa64d7ca 2017-07-25
YARA d9da1e0553b50f47d414249c02e0aa4d60ab0970 2017-07-25
YARA 587a751ff33b175d663f198e34e8aed4f9d41c56 2017-07-25
YARA e70409f91e4c0eb219d9394bf3076952fff442b1 2017-07-25