Malware.View on attack.mitre.org
China Chopper is a Web Shell hosted on Web servers to provide access back into an enterprise network that does not rely on an infected system calling back to a remote command and control server. It has been used by several threat groups.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
China Chopper's server component can upload local files. |
| T1027.002 Software Packing |
China Chopper's client component is packed with UPX. |
| T1046 Network Service Discovery |
China Chopper's server component can spider authentication portals. |
| T1059.003 Windows Command Shell |
China Chopper's server component is capable of opening a command terminal. |
| T1070.006 Timestomp |
China Chopper's server component can change the timestamp of files. |
| T1071.001 Web Protocols |
China Chopper's server component executes code sent via HTTP POST commands. |
| T1083 File and Directory Discovery |
China Chopper's server component can list directory contents. |
| T1105 Ingress Tool Transfer |
China Chopper's server component can download remote files. |
| T1110.001 Password Guessing |
China Chopper's server component can perform brute force password guessing against authentication portals. |
| T1505.003 Web Shell |
China Chopper's server component is a Web Shell payload. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.