Web Shell

T1505.003

Sub-technique of T1505 Server Software Component.View on attack.mitre.org

About this technique

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

In addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. China Chopper Web shell client).

Detection rules44

Rules on DetectionCode tagged with T1505.003.

Sigma23

RuleLevelLog source
Certificate Request Export to Exchange Webservercriticalwindows / NULL
Mailbox Export to Exchange Webservercriticalwindows / NULL
Webshell Remote Command Executioncriticallinux / NULL
Antivirus - Web Shell Detection SignaturehighNULL / antivirus
Chopper Webshell Process Patternhighwindows / process_creation
Exchange Set OabVirtualDirectory ExternalUrl Propertyhighwindows / NULL
Linux Webshell Indicatorshighlinux / process_creation
Shellshock Expressionhighlinux / NULL
Suspicious ASPX File Drop by Exchangehighwindows / file_event
Suspicious Child Process Of SQL Serverhighwindows / process_creation
Suspicious File Write to SharePoint Layouts Directoryhighwindows / file_event
Suspicious MSExchangeMailboxReplication ASPX Writehighwindows / file_event
Suspicious Process By Web Server Processhighwindows / process_creation
Suspicious Windows Strings In URIhighNULL / webserver
Webshell Detection With Command Line Keywordshighwindows / process_creation

Splunk21

RuleTypeRiskData source
Cisco Configuration Archive Logging AnalysisHuntingNULLCisco IOS Logs
Cisco Secure Firewall - Privileged Command Execution via HTTPAnomalyNULLCisco Secure Firewall Threat Defense Intrusion Event
Detect Exchange Web ShellTTPNULLSysmon EventID 11
Detect Webshell Exploit BehaviorTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Exploit Public Facing Application via Apache Commons TextAnomalyNULLNginx Access
MS Exchange Mailbox Replication service writing Active Server PagesTTPNULLSysmon EventID 1 AND Sysmon EventID 11
Spring4Shell Payload URL RequestTTPNULLNginx Access
Supernova WebshellTTPNULL
Tomcat Session Deserialization AttemptAnomalyNULLNginx Access
Tomcat Session File Upload AttemptAnomalyNULLNginx Access
W3WP Spawning ShellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Web JSP Request via URLTTPNULLNginx Access
Windows Metasploit Confluence Plugin ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Potential Web Shell Creation For VMware Workspace ONEAnomalyNULLSysmon EventID 11
Windows SharePoint Spinstall0 GET RequestTTPNULLSuricata

Groups31

Show 7 more

Software22

Campaigns13

Procedure examples66

Groups31

Used byProcedure example
GroupAgrius

Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation.

GroupAPT28

APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server.

GroupAPT29

APT29 has installed web shells on exploited Microsoft Exchange servers.

GroupAPT32

APT32 has used Web shells to maintain access to victim websites.

GroupAPT38

APT38 has used web shells for persistence or to ensure redundant access.

GroupAPT39

APT39 has installed ANTAK and ASPXSPY web shells.

GroupAPT5

APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances.

GroupBackdoorDiplomacy

BackdoorDiplomacy has used web shells to establish an initial foothold and for lateral movement within a victim's system.

View all 31 groups examples

Software22

Used byProcedure example
MalwareASPXSpy

ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS).

MalwareBUSHWALK

BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files.

MalwareChina Chopper

China Chopper's server component is a Web Shell payload.

MalwareFRAMESTING

FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs.

MalwareGLASSTOKEN

GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs.

MalwareLIGHTWIRE

LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs.

MalwareLine Runner

Line Runner is a persistent Lua-based web shell.

MalwareNeo-reGeorg

Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections.

View all 22 software examples

Campaigns13

Used byProcedure example
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the Neo-REGEORG webshell on an internet-facing server.

CampaignAPT41 DUST

APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence.

CampaignC0017

During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects.

CampaignC0032

During the C0032 campaign, TEMP.Veles planted Web shells on Outlook Exchange servers.

CampaignCutting Edge

During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING.

CampaignFrostyGoop Incident

FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence.

CampaignHomeLand Justice

For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence.

CampaignLeviathan Australian Intrusions

Leviathan relied extensively on web shell use following initial access for persistence and command execution purposes in victim environments during Leviathan Australian Intrusions.

View all 13 campaigns examples

References2

  1. Lee 2013 Open source
    Lee, T., Hanzlik, D., Ahl, I. (2013, August 7). Breaking Down the China Chopper Web Shell - Part I. Retrieved March 27, 2015.
  2. volexity_0day_sophos_FW Open source
    Adair, S., Lancaster, T., Volexity Threat Research. (2022, June 15). DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach. Retrieved July 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.