Malware.View on attack.mitre.org
WIREFIRE is a web shell written in Python that exists as trojanized logic to the visits.py component of Ivanti Connect Secure VPN appliances. WIREFIRE was used during Cutting Edge for downloading files and command execution.
| Technique | Procedure example |
|---|---|
| T1071.001 Web Protocols |
WIREFIRE can respond to specific HTTP `POST` requests to `/api/v1/cav/client/visits`. |
| T1105 Ingress Tool Transfer |
WIREFIRE has the ability to download files to compromised devices. |
| T1132.001 Standard Encoding |
WIREFIRE can Base64 encode process output sent to C2. |
| T1140 Deobfuscate/Decode Files or Information |
WIREFIRE can decode, decrypt, and decompress data received in C2 HTTP `POST` requests. |
| T1505.003 Web Shell |
WIREFIRE is a web shell that can download files to and execute arbitrary commands from compromised Ivanti Connect Secure VPNs. |
| T1554 Compromise Host Software Binary |
WIREFIRE can modify the `visits.py` component of Ivanti Connect Secure VPNs for file download and arbitrary command execution. |
| T1573.001 Symmetric Cryptography |
WIREFIRE can AES encrypt process output sent from compromised devices to C2. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.