Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware SEASHARPEE

SEASHARPEE

TLP:CLEAR
Family

AI Analysis

· 2 days ago

Executive Summary

SEASHARPEE is a web‑shell malware deployed by OilRig (APT34) to provide persistent remote access on compromised Windows servers. It facilitates command execution, file manipulation, and data exfiltration over HTTP, enabling covert operations within target networks.

Enhanced Description

SEASHARPEE is a web‑shell-based malicious component that has been publicly linked to the APT34 threat actor, commonly referred to as OilRig. The malware functions as a backdoor hosted on compromised Windows web servers, allowing adversaries to upload and execute arbitrary code through HTTP requests. It typically embeds itself within legitimate CGI or ASP files to evade detection, and leverages server‑side scripting languages (such as PHP, ASP.NET, or JSP) to provide an interactive remote interface. Once installed, SEASHARPEE offers a full range of post‑compromise capabilities: it can read and write files, spawn system processes, and exfiltrate data through the same web channel. By issuing encoded payloads via HTTP parameters, attackers can run PowerShell or command‑line binaries with elevated privileges. The web shell also supports rudimentary persistence mechanisms, such as modifying web directory permissions or creating scheduled tasks on the victim machine. Its lightweight design facilitates stealthy operations and reduces the likelihood of triggering host‑based intrusion detection systems. The threat actor uses SEASHARPEE mainly to establish long‑term access within targeted infrastructures—often oil, gas, and petrochemical enterprises—to gather intelligence, exfiltrate intellectual property, or conduct lateral movements across internal networks. By exploiting web servers that are already exposed to the internet, OilRig can bypass perimeter defenses and maintain covert command and control channels. Overall, SEASHARPEE exemplifies the industry shift toward server‑side shells as a preferred C2 vector for APT actors seeking persistence, data theft, and covert operations.

Key Capabilities

  • Provides an interactive shell via HTTP requests
  • Uploads, executes, and deletes arbitrary files
  • Supports PowerShell/Windows command‑line execution
  • Uses credential theft or API misuse for lateral movement
  • Offers basic persistence mechanisms such as scheduled tasks

ATT&CK Techniques

T1505
T1059.003
T1104

Recommended Actions

  • Configure web servers to deny script execution outside known application directories.
  • Deploy host‑based detection rules for suspicious CGI/ASP file modifications.
  • Monitor outbound HTTP traffic for unexplained base64‑encoded parameters. Implement WAF policies that block file uploads of executable payloads.
  • Enforce strict permission checks on server configuration files and scheduled task objects.
  • Use multi‑factor authentication to restrict privileged accounts that can install web shells.

Suggested Tags

OilRig
APT34
Web shell
Command and Control
Windows malware
Persistence
Data exfiltration

Confidence Assessment

Confidence in the core facts (web‑shell nature, association with OilRig) is moderate due to cited sources. However, detailed behavior—payload handling, persistence strategies—and exact deployment paths are not fully validated, creating analytical gaps.

Description

SEASHARPEE is a Web shell that has been used by OilRig. (Citation: FireEye APT34 Webinar Dec 2017)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.