Malware.View on attack.mitre.org
BUSHWALK is a web shell written in Perl that was inserted into the legitimate querymanifest.cgi file on compromised Ivanti Connect Secure VPNs during Cutting Edge.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
BUSHWALK can encrypt the resulting data generated from C2 commands with RC4. |
| T1105 Ingress Tool Transfer |
BUSHWALK can write malicious payloads sent through a web request’s command parameter. |
| T1140 Deobfuscate/Decode Files or Information |
BUSHWALK can Base64 decode and RC4 decrypt malicious payloads sent through a web request’s command parameter. |
| T1205 Traffic Signaling |
BUSHWALK can modify the `DSUserAgentCap.pm` Perl module on Ivanti Connect Secure VPNs and either activate or deactivate depending on the value of the user agent in incoming HTTP requests. |
| T1505.003 Web Shell |
BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files. |
| T1554 Compromise Host Software Binary |
BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.