ATT&CKSoftwareCaterpillar WebShell

Caterpillar WebShell

S0572

Malware.View on attack.mitre.org

About this malware

Caterpillar WebShell is a self-developed Web Shell tool created by the group Volatile Cedar.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

Caterpillar WebShell has a module to collect information from the local database.

T1007
System Service Discovery

Caterpillar WebShell can obtain a list of the services from a system.

T1014
Rootkit

Caterpillar WebShell has a module to use a rootkit on a system.

T1016
System Network Configuration Discovery

Caterpillar WebShell can gather the IP address from the victim's machine using the IP config command.

T1033
System Owner/User Discovery

Caterpillar WebShell can obtain a list of user accounts from a victim's machine.

T1041
Exfiltration Over C2 Channel

Caterpillar WebShell can upload files over the C2 channel.

T1046
Network Service Discovery

Caterpillar WebShell has a module to use a port scanner on a system.

T1057
Process Discovery

Caterpillar WebShell can gather a list of processes running on the machine.

T1059.003
Windows Command Shell

Caterpillar WebShell can run commands on the compromised asset with CMD functions.

T1069.001
Local Groups

Caterpillar WebShell can obtain a list of local groups of users from a system.

T1082
System Information Discovery

Caterpillar WebShell has a module to gather information from the compromised asset, including the computer version, computer name, IIS version, and more.

T1083
File and Directory Discovery

Caterpillar WebShell can search for files in directories.

T1105
Ingress Tool Transfer

Caterpillar WebShell has a module to download and upload files to the system.

T1110
Brute Force

Caterpillar WebShell has a module to perform brute force attacks on a system.

T1112
Modify Registry

Caterpillar WebShell has a command to modify a Registry key.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ClearSky Lebanese Cedar Jan 2021 Open source
    ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.