ATT&CKReferencesTalos Seduploader Oct 2017

Talos Seduploader Oct 2017

Mercer, W., et al. (2017, October 22). "Cyber Conflict" Decoy Document Used in Real Cyber Conflict. Retrieved November 2, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupAPT28

APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4.

T1027.013
Encrypted/Encoded File
MalwareJHUHUGIT

Many strings in JHUHUGIT are obfuscated with a XOR algorithm.

T1037.001
Logon Script (Windows)
MalwareJHUHUGIT

JHUHUGIT has registered a Windows shell script under the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

T1059.003
Windows Command Shell
MalwareJHUHUGIT

JHUHUGIT uses a .bat file to execute a .dll.

T1059.003
Windows Command Shell
GroupAPT28

An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads.

T1105
Ingress Tool Transfer
MalwareJHUHUGIT

JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine.

T1113
Screen Capture
MalwareJHUHUGIT

A JHUHUGIT variant takes screenshots by simulating the user pressing the "Take Screenshot" key (VK_SCREENSHOT), accessing the screenshot saved in the clipboard, and converting it to a JPG image.

T1218.011
Rundll32
MalwareJHUHUGIT

JHUHUGIT is executed using rundll32.exe.

T1546.015
Component Object Model Hijacking
MalwareJHUHUGIT

JHUHUGIT has used COM hijacking to establish persistence by hijacking a class named MMDeviceEnumerator and also by registering the payload as a Shell Icon Overlay handler COM object ({3543619C-D563-43f7-95EA-4DA7E1CC396A}).

T1564.001
Hidden Files and Directories
GroupAPT28

APT28 has saved files with hidden file attributes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.