Sharik Back For More After Php.Net Compromise
ID: ed683e97-0391-5934-9492-426f2542f153
STIX ID: report--ed683e97-0391-5934-9492-426f2542f153
Feed Name: Zscaler Security Research Blog
This report analyzes the 'Sharik' Trojan — a backdoor that injects into legitimate processes, creates persistent autorun mechanisms (including explorer.exe hooks), and communicates with command-and-control servers over HTTP (commonly on non-standard port 35618). The author enumerates many drop URLs and phone-home IPs/URLs as IOCs, highlights overlap with other malware families (Nymaim, Fareit), and recommends monitoring or closing port 35618 and investigating traffic matching the listed indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
