Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, July 30). Sakula Malware Family. Retrieved January 26, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareSakula | Sakula uses single-byte XOR obfuscation to obfuscate many of its files. |
| T1059.003 Windows Command Shell |
MalwareSakula | Sakula calls cmd.exe to run various DLL files via rundll32 and also to perform file cleanup. Sakula also has the capability to invoke a reverse shell. |
| T1070.004 File Deletion |
MalwareSakula | Some Sakula samples use cmd.exe to delete temporary files. |
| T1071.001 Web Protocols |
MalwareSakula | Sakula uses HTTP for C2. |
| T1105 Ingress Tool Transfer |
MalwareSakula | Sakula has the capability to download files. |
| T1218.011 Rundll32 |
MalwareSakula | Sakula calls cmd.exe to run various DLL files via rundll32. |
| T1543.003 Windows Service |
MalwareSakula | Some Sakula samples install themselves as services for persistence by calling WinExec with the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSakula | Most Sakula samples maintain persistence by setting the Registry Run key |
| T1548.002 Bypass User Account Control |
MalwareSakula | Sakula contains UAC bypass code for both 32- and 64-bit systems. |
| T1573.001 Symmetric Cryptography |
MalwareSakula | Sakula encodes C2 traffic with single-byte XOR keys. |
| T1574.001 DLL |
MalwareSakula | Sakula uses DLL side-loading, typically using a digitally signed sample of Kaspersky Anti-Virus (AV) 6.0 for Windows Workstations or McAfee's Outlook Scan About Box to load malicious DLL files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.