logo

Sharik Back For More After Php.Net Compromise

ID: ed683e97-0391-5934-9492-426f2542f153

STIX ID: report--ed683e97-0391-5934-9492-426f2542f153

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes the 'Sharik' Trojan — a backdoor that injects into legitimate processes, creates persistent autorun mechanisms (including explorer.exe hooks), and communicates with command-and-control servers over HTTP (commonly on non-standard port 35618). The author enumerates many drop URLs and phone-home IPs/URLs as IOCs, highlights overlap with other malware families (Nymaim, Fareit), and recommends monitoring or closing port 35618 and investigating traffic matching the listed indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.