ATT&CKSoftwareP.A.S. Webshell

P.A.S. Webshell

S0598

Malware.View on attack.mitre.org

About this malware

P.A.S. Webshell is a publicly available multifunctional PHP webshell in use since at least 2016 that provides remote access and execution on target web servers.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

P.A.S. Webshell has the ability to copy files on a compromised host.

T1027
Obfuscated Files or Information

P.A.S. Webshell can use encryption and base64 encoding to hide strings and to enforce access control once deployed.

T1046
Network Service Discovery

P.A.S. Webshell can scan networks for open ports and listening services.

T1059
Command and Scripting Interpreter

P.A.S. Webshell has the ability to create reverse shells with Perl scripts.

T1070.004
File Deletion

P.A.S. Webshell can delete scripts from a subdirectory of /tmp after they are run.

T1071.001
Web Protocols

P.A.S. Webshell can issue commands via HTTP POST.

T1083
File and Directory Discovery

P.A.S. Webshell has the ability to list files and file characteristics including extension, size, ownership, and permissions.

T1087.001
Local Account

P.A.S. Webshell can display the /etc/passwd file on a compromised host.

T1105
Ingress Tool Transfer

P.A.S. Webshell can upload and download files to and from compromised hosts.

T1110.001
Password Guessing

P.A.S. Webshell can use predefined users and passwords to execute brute force attacks against SSH, FTP, POP3, MySQL, MSSQL, and PostgreSQL services.

T1140
Deobfuscate/Decode Files or Information

P.A.S. Webshell can use a decryption mechanism to process a user supplied password and allow execution.

T1213.006
Databases

P.A.S. Webshell has the ability to list and extract data from SQL databases.

T1222.002
Linux and Mac Permissions

P.A.S. Webshell has the ability to modify file permissions.

T1505.003
Web Shell

P.A.S. Webshell can gain remote access and execution on target web servers.

T1518
Software Discovery

P.A.S. Webshell can list PHP server configuration details.

Groups that use it2

Campaigns0

None recorded.

References1

  1. ANSSI Sandworm January 2021 Open source
    ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.