PULSE NAME
Shakti Trojan: Document Thief
WHITE AlienVault 2016-08-15 Modified: 2016-08-16
9
IOCs
LOW VOLUME
While some ransomware (i.e. Chimera) give bogus threats about stealing and releasing private files, there are other malware families that in fact have made this possibility a reality. Recently, Bleeping Computer published a short article about an unrecognized Trojan that grabs documents from the attacked computer and uploads them into a malicious server. Looking at the characteristics of the tool, we suspect that it has been prepared for the purpose of corporate espionage. So far, no AV has given any meaningful identification to this malware—it is detected under generic names. Since not much is known about its internals, we decided to take a closer look. In the unpacked core we found strings suggesting that the authors named the project Shakti, which means “power” in Hindi or may also be a reference to the Shakti goddess. That’s why we refer to this malware as Shakti Trojan.
Indicators of Compromise (9)
All domain FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
domain web4solution.net 2016-08-15
domain securedesignus.com 2016-08-15
domain securedesignuk.com 2016-08-15
FileHash-MD5 d9181d69c40fc95d7d27448f5ece1878 2016-08-15
FileHash-MD5 bc05977b3f543ac1388c821274cbd22e 2016-08-15
FileHash-MD5 6992370821f8fbeea4a96f7be8015967 2016-08-15
FileHash-MD5 8ea35293cbb0712a520c7b89059d5a2a 2016-08-15
FileHash-MD5 7d0ebb99055e931e03f7981843fdb540 2016-08-15
FileHash-MD5 b1380af637b4011e674644e0a1a53a64 2016-08-15