Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
SeaDuke has been packed with the UPX packer. |
| T1059.001 PowerShell |
SeaDuke uses a module to execute Mimikatz with PowerShell to perform Pass the Ticket. |
| T1059.003 Windows Command Shell |
SeaDuke is capable of executing commands. |
| T1070.004 File Deletion |
SeaDuke can securely delete files, including deleting itself from the victim. |
| T1071.001 Web Protocols |
SeaDuke uses HTTP and HTTPS for C2. |
| T1078 Valid Accounts |
Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials. |
| T1105 Ingress Tool Transfer |
SeaDuke is capable of uploading and downloading files. |
| T1114.002 Remote Email Collection |
Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials. |
| T1132.001 Standard Encoding |
SeaDuke C2 traffic is base64-encoded. |
| T1546.003 Windows Management Instrumentation Event Subscription |
SeaDuke uses an event filter in WMI code to execute a previously dropped executable shortly after system startup. |
| T1547.001 Registry Run Keys / Startup Folder |
SeaDuke is capable of persisting via the Registry Run key or a .lnk file stored in the Startup directory. |
| T1547.009 Shortcut Modification |
SeaDuke is capable of persisting via a .lnk file stored in the Startup directory. |
| T1550.003 Pass the Ticket |
Some SeaDuke samples have a module to use pass the ticket with Kerberos for authentication. |
| T1560.002 Archive via Library |
SeaDuke compressed data with zlib prior to sending it over C2. |
| T1573.001 Symmetric Cryptography |
SeaDuke C2 traffic has been encrypted with RC4 and AES. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.