FRAMESTING is a Python web shell that was used during Cutting Edge to embed into an Ivanti Connect Secure Python package for command execution.[1]
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols |
FRAMESTING can retrieve C2 commands from values stored in the |
| Enterprise | T1059 | .006 | Command and Scripting Interpreter: Python |
FRAMESTING is a Python web shell that can embed in the Ivanti Connect Secure CAV Python package.[1] |
| Enterprise | T1554 | Compromise Host Software Binary |
FRAMESTING can embed itself in the CAV Python package of an Ivanti Connect Secure VPN located in |
|
| Enterprise | T1001 | Data Obfuscation |
FRAMESTING can send and receive zlib compressed data within |
|
| .003 | Protocol Impersonation |
FRAMESTING uses a cookie named |
||
| Enterprise | T1140 | Deobfuscate/Decode Files or Information |
FRAMESTING can decompress data received within |
|
| Enterprise | T1505 | .003 | Server Software Component: Web Shell |
FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs.[1] |
| ID | Name | Description |
|---|---|---|
| C0029 | Cutting Edge |