Malware.View on attack.mitre.org
PULSECHECK is a web shell written in Perl that was used by APT5 as early as 2020 including against Pulse Secure VPNs at US Defense Industrial Base (DIB) companies.
| Technique | Procedure example |
|---|---|
| T1059.004 Unix Shell |
PULSECHECK can use Unix shell script for command execution. |
| T1071.001 Web Protocols |
PULSECHECK can check HTTP request headers for a specific backdoor key and if found will output the result of the command in the variable `HTTP_X_CMD.` |
| T1132.001 Standard Encoding |
PULSECHECK can base-64 encode encrypted data sent through C2. |
| T1505.003 Web Shell |
PULSECHECK is a web shell that can enable command execution on compromised servers. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.