Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. STEADYPULSE

STEADYPULSE

STEADYPULSE is a web shell that infects targeted Pulse Secure VPN servers through modification of a legitimate Perl script that was used as early as 2020 including in activity against US Defense Industrial Base (DIB) entities.[1]

ID: S1112
Type: MALWARE
Platforms: Network Devices
Version: 1.1
Created: 09 February 2024
Last Modified: 15 April 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1071.001Application Layer Protocol:Web Protocols

STEADYPULSE can parse web requests made to a targeted server to determine the next stage of execution.[1]

EnterpriseT1132.001Data Encoding:Standard Encoding

STEADYPULSE can transmit URL encoded data over C2.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

STEADYPULSE can URL decode key/value pairs sent over C2.[1]

EnterpriseT1105Ingress Tool Transfer

STEADYPULSE can add lines to a Perl script on a targeted server to import additional Perl modules.[1]

EnterpriseT1505.003Server Software Component:Web Shell

STEADYPULSE is a web shell that can enable the execution of arbitrary commands on compromised web servers.[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp