Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1505.003 Web Shell |
MalwareSEASHARPEE | SEASHARPEE is a Web shell. |
| T1505.003 Web Shell |
MalwarereGeorg | reGeorg is a web shell that has been installed on exposed web servers for access to victim environments. |
| T1505.003 Web Shell |
MalwareBUSHWALK | BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files. |
| T1505.003 Web Shell |
MalwareP.A.S. Webshell | P.A.S. Webshell can gain remote access and execution on target web servers. |
| T1505.003 Web Shell |
MalwareGLASSTOKEN | GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs. |
| T1505.003 Web Shell |
MalwareASPXSpy | ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS). |
| T1505.003 Web Shell |
MalwareChina Chopper | China Chopper's server component is a Web Shell payload. |
| T1505.003 Web Shell |
MalwareSnappyTCP | SnappyTCP is a reverse TCP shell with command and control capabilities used for persistence purposes. |
| T1505.003 Web Shell |
MalwareLIGHTWIRE | LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs. |
| T1505.003 Web Shell |
MalwareLine Runner | Line Runner is a persistent Lua-based web shell. |
| T1505.003 Web Shell |
MalwareRAPIDPULSE | RAPIDPULSE is a web shell that is capable of arbitrary file read on targeted web servers to exfiltrate items of interest on the victim device. |
| T1505.003 Web Shell |
MalwarePHPsert | PHPsert can use the .php assert function to execute attacker-provided code and maintain persistence on targeted web servers. |
| T1505.003 Web Shell |
MalwarePULSECHECK | PULSECHECK is a web shell that can enable command execution on compromised servers. |
| T1505.003 Web Shell |
MalwareOwaAuth | OwaAuth is a Web shell that appears to be exclusively used by Threat Group-3390. It is installed as an ISAPI filter on Exchange servers and shares characteristics with the China Chopper Web shell. |
| T1505.003 Web Shell |
MalwareSUPERNOVA | SUPERNOVA is a Web shell. |
| T1505.003 Web Shell |
MalwareNeo-reGeorg | Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections. |
| T1505.003 Web Shell |
MalwareFRAMESTING | FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs. |
| T1505.003 Web Shell |
MalwareWIREFIRE | WIREFIRE is a web shell that can download files to and execute arbitrary commands from compromised Ivanti Connect Secure VPNs. |
| T1505.003 Web Shell |
MalwareSTEADYPULSE | STEADYPULSE is a web shell that can enable the execution of arbitrary commands on compromised web servers. |
| T1505.003 Web Shell |
MalwarePHASEJAM | PHASEJAM has inserted Perl-based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance. |
| T1505.003 Web Shell |
MalwareSLIGHTPULSE | SLIGHTPULSE is a web shell that can read, write, and execute files on compromised servers. |
| T1505.003 Web Shell |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has created web shells that facilitate actions on the victim host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.