Currently viewing ATT&CK v7.2 which was live between July 8, 2020 and October 26, 2020. Learn more about the versioning system or see the live site.
Register to stream the next session of ATT&CKcon Power Hour November 12

SEASHARPEE

SEASHARPEE is a Web shell that has been used by APT34. [1]

ID: S0185
Type: MALWARE
Platforms: Windows
Version: 1.1
Created: 16 January 2018
Last Modified: 30 March 2020

Techniques Used

Domain ID Name Use
Enterprise T1059 .003 Command and Scripting Interpreter: Windows Command Shell

SEASHARPEE can execute commands on victims.[1]

Enterprise T1070 .006 Indicator Removal on Host: Timestomp

SEASHARPEE can timestomp files on victims using a Web shell.[1]

Enterprise T1105 Ingress Tool Transfer

SEASHARPEE can download remote files onto victims.[1]

Enterprise T1505 .003 Server Software Component: Web Shell

SEASHARPEE is a Web shell.[1]

Groups That Use This Software

ID Name References
G0049 OilRig

[1]

References