Sub-technique of T1505 Server Software Component.View on attack.mitre.org
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
In addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. China Chopper Web shell client).
Rules on DetectionCode tagged with T1505.003.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco Configuration Archive Logging Analysis | Hunting | NULL | Cisco IOS Logs |
| Cisco Secure Firewall - Privileged Command Execution via HTTP | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Detect Exchange Web Shell | TTP | NULL | Sysmon EventID 11 |
| Detect Webshell Exploit Behavior | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Exploit Public Facing Application via Apache Commons Text | Anomaly | NULL | Nginx Access |
| MS Exchange Mailbox Replication service writing Active Server Pages | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 11 |
| Spring4Shell Payload URL Request | TTP | NULL | Nginx Access |
| Supernova Webshell | TTP | NULL | |
| Tomcat Session Deserialization Attempt | Anomaly | NULL | Nginx Access |
| Tomcat Session File Upload Attempt | Anomaly | NULL | Nginx Access |
| W3WP Spawning Shell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Web JSP Request via URL | TTP | NULL | Nginx Access |
| Windows Metasploit Confluence Plugin Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Potential Web Shell Creation For VMware Workspace ONE | Anomaly | NULL | Sysmon EventID 11 |
| Windows SharePoint Spinstall0 GET Request | TTP | NULL | Suricata |
| Windows SharePoint Spinstall0 Webshell File Creation | TTP | NULL | Sysmon EventID 11 |
| Windows SharePoint ToolPane Endpoint Exploitation Attempt | TTP | NULL | Suricata |
| Windows Suspicious Child Process Spawned From WebServer | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows TeamCity Payload Execution from Temp Directory | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows TeamCity Plugin Installed | Anomaly | NULL | Sysmon EventID 11 |
| Windows WSUS Spawning Shell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation. |
| GroupAPT28 | APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server. |
| GroupAPT29 | APT29 has installed web shells on exploited Microsoft Exchange servers. |
| GroupAPT32 | APT32 has used Web shells to maintain access to victim websites. |
| GroupAPT38 | APT38 has used web shells for persistence or to ensure redundant access. |
| GroupAPT39 | APT39 has installed ANTAK and ASPXSPY web shells. |
| GroupAPT5 | APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances. |
| GroupBackdoorDiplomacy | BackdoorDiplomacy has used web shells to establish an initial foothold and for lateral movement within a victim's system. |
| Used by | Procedure example |
|---|---|
| MalwareASPXSpy | ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS). |
| MalwareBUSHWALK | BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files. |
| MalwareChina Chopper | China Chopper's server component is a Web Shell payload. |
| MalwareFRAMESTING | FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs. |
| MalwareGLASSTOKEN | GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs. |
| MalwareLIGHTWIRE | LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs. |
| MalwareLine Runner | Line Runner is a persistent Lua-based web shell. |
| MalwareNeo-reGeorg | Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections. |
| Used by | Procedure example |
|---|---|
| Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the Neo-REGEORG webshell on an internet-facing server. |
| CampaignAPT41 DUST | APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence. |
| CampaignC0017 | During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles planted Web shells on Outlook Exchange servers. |
| CampaignCutting Edge | During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING. |
| CampaignFrostyGoop Incident | FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence. |
| CampaignHomeLand Justice | For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence. |
| CampaignLeviathan Australian Intrusions | Leviathan relied extensively on web shell use following initial access for persistence and command execution purposes in victim environments during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.