ATT&CKReferencesUnit 42 SeaDuke 2015

Unit 42 SeaDuke 2015

Grunzweig, J.. (2015, July 14). Unit 42 Technical Analysis: Seaduke. Retrieved August 3, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareSeaDuke

SeaDuke has been packed with the UPX packer.

T1059.003
Windows Command Shell
MalwareSeaDuke

SeaDuke is capable of executing commands.

T1105
Ingress Tool Transfer
MalwareSeaDuke

SeaDuke is capable of uploading and downloading files.

T1132.001
Standard Encoding
MalwareSeaDuke

SeaDuke C2 traffic is base64-encoded.

T1547.001
Registry Run Keys / Startup Folder
MalwareSeaDuke

SeaDuke is capable of persisting via the Registry Run key or a .lnk file stored in the Startup directory.

T1547.009
Shortcut Modification
MalwareSeaDuke

SeaDuke is capable of persisting via a .lnk file stored in the Startup directory.

T1573.001
Symmetric Cryptography
MalwareSeaDuke

SeaDuke C2 traffic has been encrypted with RC4 and AES.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.