ATT&CKReferencesDell Sakula

Dell Sakula

Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, July 30). Sakula Malware Family. Retrieved January 26, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareSakula

Sakula uses single-byte XOR obfuscation to obfuscate many of its files.

T1059.003
Windows Command Shell
MalwareSakula

Sakula calls cmd.exe to run various DLL files via rundll32 and also to perform file cleanup. Sakula also has the capability to invoke a reverse shell.

T1070.004
File Deletion
MalwareSakula

Some Sakula samples use cmd.exe to delete temporary files.

T1071.001
Web Protocols
MalwareSakula

Sakula uses HTTP for C2.

T1105
Ingress Tool Transfer
MalwareSakula

Sakula has the capability to download files.

T1218.011
Rundll32
MalwareSakula

Sakula calls cmd.exe to run various DLL files via rundll32.

T1543.003
Windows Service
MalwareSakula

Some Sakula samples install themselves as services for persistence by calling WinExec with the net start argument.

T1547.001
Registry Run Keys / Startup Folder
MalwareSakula

Most Sakula samples maintain persistence by setting the Registry Run key SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ in the HKLM or HKCU hive, with the Registry value and file name varying by sample.

T1548.002
Bypass User Account Control
MalwareSakula

Sakula contains UAC bypass code for both 32- and 64-bit systems.

T1573.001
Symmetric Cryptography
MalwareSakula

Sakula encodes C2 traffic with single-byte XOR keys.

T1574.001
DLL
MalwareSakula

Sakula uses DLL side-loading, typically using a digitally signed sample of Kaspersky Anti-Virus (AV) 6.0 for Windows Workstations or McAfee's Outlook Scan About Box to load malicious DLL files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.