PULSE NAME
Sakula Reloaded
WHITE AlienVault 2015-11-18 Modified: 2017-07-25
23
IOCs
MEDIUM VOLUME
Sakula is a well known malware variant linked to several significant targeted intrusion campaigns over the past 2-3 years. This remote access toolkit has been publicly examined multiple times by the threat intelligence community. CrowdStrike has released two blog posts detailing Sakula campaigns and continues to investigate its usage. In the past two years, two campaigns of Sakula activity stand out as being particularly significant – the “French Aerospace” Campaign and the “Ironman” Campaign. In recent months, CrowdStrike has observed limited use of what appears to be a third Sakula variant.
Indicators of Compromise (3 / 23 total)
All domain URL hostname CVE YARA FileHash-SHA256 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 38e21f0b87b3052b536408fdf59185f8b3d210b9 2017-07-24
FileHash-SHA1 5d201a0fb0f4a96cefc5f73effb61acff9c818e1 2017-07-24
FileHash-SHA1 ffb1d8ea3039d3d5eb7196d27f5450cac0ea4f34 2017-07-24