Grunzweig, J.. (2015, July 14). Unit 42 Technical Analysis: Seaduke. Retrieved August 3, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareSeaDuke | SeaDuke has been packed with the UPX packer. |
| T1059.003 Windows Command Shell |
MalwareSeaDuke | SeaDuke is capable of executing commands. |
| T1105 Ingress Tool Transfer |
MalwareSeaDuke | SeaDuke is capable of uploading and downloading files. |
| T1132.001 Standard Encoding |
MalwareSeaDuke | SeaDuke C2 traffic is base64-encoded. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSeaDuke | SeaDuke is capable of persisting via the Registry Run key or a .lnk file stored in the Startup directory. |
| T1547.009 Shortcut Modification |
MalwareSeaDuke | SeaDuke is capable of persisting via a .lnk file stored in the Startup directory. |
| T1573.001 Symmetric Cryptography |
MalwareSeaDuke | SeaDuke C2 traffic has been encrypted with RC4 and AES. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.