ATT&CKSoftwarePULSECHECK

PULSECHECK

S1108

Malware.View on attack.mitre.org

About this malware

PULSECHECK is a web shell written in Perl that was used by APT5 as early as 2020 including against Pulse Secure VPNs at US Defense Industrial Base (DIB) companies.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1059.004
Unix Shell

PULSECHECK can use Unix shell script for command execution.

T1071.001
Web Protocols

PULSECHECK can check HTTP request headers for a specific backdoor key and if found will output the result of the command in the variable `HTTP_X_CMD.`

T1132.001
Standard Encoding

PULSECHECK can base-64 encode encrypted data sent through C2.

T1505.003
Web Shell

PULSECHECK is a web shell that can enable command execution on compromised servers.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant Pulse Secure Zero-Day April 2021 Open source
    Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.