LIGHTWIRE

LIGHTWIRELIGHTWIRE

Description

The original LIGHTWIRE webshell sample contains a simpler obfuscation routine. It will initialize an RC4 object and then immediately use the RC4 object to decrypt the issued command./nMandiant has identified an additional variant of the LIGHTWIRE web shell that inserts itself into a legitimate component of the VPN gateway, compcheckresult.cgi./nThe new sample utilizes the same GET parameters as the original LIGHTWIRE sample./nThe new variant of LIGHTWIRE features a different obfuscation routine. It first assigns a string scalar variable to $useCompOnly. Next, it will use the Perl tr operator to transform the string using a character-by-character translation. The key is then Base64-decoded and used to RC4 decrypt the incoming request. Finally, the issued command is executed by calling eval.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
LIGHTDART
Software
LIGHTBOLT
Software
LitePower
Software
Light
Software
NETWIRE
Software
BUSHWALK
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.