Lee 2013

Lee, T., Hanzlik, D., Ahl, I. (2013, August 7). Breaking Down the China Chopper Web Shell - Part I. Retrieved March 27, 2015.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareChina Chopper

China Chopper's server component can upload local files.

T1027.002
Software Packing
MalwareChina Chopper

China Chopper's client component is packed with UPX.

T1059.003
Windows Command Shell
MalwareChina Chopper

China Chopper's server component is capable of opening a command terminal.

T1070.006
Timestomp
MalwareChina Chopper

China Chopper's server component can change the timestamp of files.

T1105
Ingress Tool Transfer
MalwareChina Chopper

China Chopper's server component can download remote files.

T1505.003
Web Shell
MalwareChina Chopper

China Chopper's server component is a Web Shell payload.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.