ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1505.003×

22 examples

TechniqueUsed byProcedure example
T1505.003
Web Shell
MalwareSEASHARPEE

SEASHARPEE is a Web shell.

T1505.003
Web Shell
MalwarereGeorg

reGeorg is a web shell that has been installed on exposed web servers for access to victim environments.

T1505.003
Web Shell
MalwareBUSHWALK

BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files.

T1505.003
Web Shell
MalwareP.A.S. Webshell

P.A.S. Webshell can gain remote access and execution on target web servers.

T1505.003
Web Shell
MalwareGLASSTOKEN

GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs.

T1505.003
Web Shell
MalwareASPXSpy

ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS).

T1505.003
Web Shell
MalwareChina Chopper

China Chopper's server component is a Web Shell payload.

T1505.003
Web Shell
MalwareSnappyTCP

SnappyTCP is a reverse TCP shell with command and control capabilities used for persistence purposes.

T1505.003
Web Shell
MalwareLIGHTWIRE

LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs.

T1505.003
Web Shell
MalwareLine Runner

Line Runner is a persistent Lua-based web shell.

T1505.003
Web Shell
MalwareRAPIDPULSE

RAPIDPULSE is a web shell that is capable of arbitrary file read on targeted web servers to exfiltrate items of interest on the victim device.

T1505.003
Web Shell
MalwarePHPsert

PHPsert can use the .php assert function to execute attacker-provided code and maintain persistence on targeted web servers.

T1505.003
Web Shell
MalwarePULSECHECK

PULSECHECK is a web shell that can enable command execution on compromised servers.

T1505.003
Web Shell
MalwareOwaAuth

OwaAuth is a Web shell that appears to be exclusively used by Threat Group-3390. It is installed as an ISAPI filter on Exchange servers and shares characteristics with the China Chopper Web shell.

T1505.003
Web Shell
MalwareSUPERNOVA

SUPERNOVA is a Web shell.

T1505.003
Web Shell
MalwareNeo-reGeorg

Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections.

T1505.003
Web Shell
MalwareFRAMESTING

FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs.

T1505.003
Web Shell
MalwareWIREFIRE

WIREFIRE is a web shell that can download files to and execute arbitrary commands from compromised Ivanti Connect Secure VPNs.

T1505.003
Web Shell
MalwareSTEADYPULSE

STEADYPULSE is a web shell that can enable the execution of arbitrary commands on compromised web servers.

T1505.003
Web Shell
MalwarePHASEJAM

PHASEJAM has inserted Perl-based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance.

T1505.003
Web Shell
MalwareSLIGHTPULSE

SLIGHTPULSE is a web shell that can read, write, and execute files on compromised servers.

T1505.003
Web Shell
MalwareSPAWNCHIMERA

SPAWNCHIMERA has created web shells that facilitate actions on the victim host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.