PULSE NAME
IOC - Inside Shanya, a packer-as-a-service fueling modern attacks
WHITE celestre 2025-12-09 Modified: 2025-12-09
26
IOCs
MEDIUM VOLUME
We have covered packer-as-a-service offerings from the computer underworld in the past, previously dissecting impersonation campaigns and the rise of HeartCrypt, both popular among ransomware groups. However, it is a fast-changing landscape, and now we are watching a new incarnation of the same type of service: the Shanya crypter — already favored by ransomware groups and taking over (to some degree) the role that HeartCrypt has played in the ransomware toolkit. We’ll look at its apparent origins, unpack the code, and examine a targeted infection leveraging this tool. Sophos protections against this specific packer are covered at the end of the article.
Indicators of Compromise (5 / 26 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 247890c8e1787f3836a9085244b70e83 MD5 of 6645297a0a423564f99b9f474b0df234d6613d04df48a94cb67f541b8eb829d1 2025-12-09
FileHash-MD5 29236d33201697a40042b3325414c593 MD5 of 59906b022adfc6f63903adbdbb64c82881e0b1664d6b7f7ee42319019fcb3d7e 2025-12-09
FileHash-MD5 34fe39190f861681e61a46fe8162d3bc MD5 of 087216ee05746cc264752b0623dc6a1e32cddc0ca088832672e6dd356d394393 2025-12-09
FileHash-MD5 54de95cc33834a2f877ba4842860af27 MD5 of 95a6f6e79c1842cea3603df3209fddc12aeb4fc77d1c58a852f877b1eaa9c4c9 2025-12-09
FileHash-MD5 b1a5c56edf70f327d7c7dbff3d861a94 MD5 of 2bfb560c7b34a2b4c30db711900d6e56d86f754f4fbeebe551b8c67bc30a2b36 2025-12-09