If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/software/S9014 - PHASEJAM, Software S9014 | MIT.

site address: attack.mitre.org/software/S9014 redirected to: attack.mitre.org/software/S9014

site title: PHASEJAM, Software S9014 MITRE ATT&CK®

Our opinion (on Thursday 20 August 2026 18:04:14 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

phasejam, techniques, used, references, enterprise, layer,

Text of the page (most frequently used words):
the (22), phasejam (21), #enterprise (19), has (17), and (15), att (11), all (10), 2026 (8), ivanti (7), connect (7), secure (7), software (6), data (6), files (6), commands (6), ics (5), mobile (5), none (5), components (5), legitimate (5), appliance (5), shell (5), version (5), mitre (4), techniques (4), that (4), with (4), execution (4), compromised (4), network (4), base64 (4), command (4), remotedebug (4), used (4), execute (4), upgrades (4), upgrade (4), are (3), cti (3), defenses (3), april (3), dragos (3), appliances (3), cgi (3), web (3), actors (3), code (3), 003 (3), encoded (3), file (3), information (3), script (3), home (3), bin (3), ability (3), bash (3), modify (3), system (3), modified (3), corporation (2), use (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), 2025 (2), january (2), retrieved (2), process (2), server (2), into (2), provided (2), threat (2), obfuscated (2), tool (2), linux (2), fake (2), html (2), progress (2), bar (2), device (2), dsupgrade (2), tools (2), decode (2), leveraged (2), s9014 (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, john, wolfram, josh, murchie, matt, lin, daniel, ainsworth, robert, wallace, dimiter, andonov, dhanesh, kizhakkinan, jacob, thompson, vpn, targeted, new, zero, day, exploitation, march, cybersecurity, report, year, review, petrochemicals, focus, references, disabled, service, stop, t1489, inserted, perl, based, shells, remote, access, capabilities, component, t1505, launched, webshell, using, module, decoded, mime, encrypted, 013, obfuscation, 010, t1027, renamed, allowing, threats, write, malicious, bak, rename, utilities, masquerading, t1036, upload, onto, ingress, transfer, t1105, exfiltrate, from, victim, exfiltration, over, channel, t1041, via, also, stream, editor, sed, unix, configuration, modification, event, triggered, 004, t1546, prevented, intercepting, rendering, through, function, called, which, allowed, remain, under, control, adversary, processupgradedisplay, spoof, blocks, altering, disable, t1685, deobfuscate, t1140, within, its, generate, mimics, running, sleep, delay, t1678, blocked, systems, falsely, indicates, successful, while, operating, older, manipulation, t1565, enable, persistence, including, inserting, modifying, block, overwriting, arbitrary, when, specific, parameters, restauth, getcomponent, compromise, host, binary, t1554, native, associated, cli, scripting, interpreter, 008, t1059, name, domain, view, download, layer, navigator, layers, live, permalink, may, last, created, intelligence, contributors, devices, platforms, malware, type, dropper, written, modifies, was, first, reported, previously, been, people, republic, china, prc, affiliated, identified, unc5221, sylvanite, open, join, october, mclean, for, hotel, location, details, can, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, about, get, started, detections,


Text of the page (random words):
phasejam software s9014 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home software phasejam phasejam phasejam is a dropper written as a bash shell script that modifies ivanti connect secure appliance components phasejam was first reported in january 2025 phasejam has previously been leveraged by people s republic of china prc affiliated actors identified as unc5221 and sylvanite 1 2 id s9014 ⓘ type malware ⓘ platforms linux network devices contributors dragos threat intelligence version 1 0 created 16 april 2026 last modified 12 may 2026 version permalink live version att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1059 008 command and scripting interpreter network device cli phasejam has leveraged native commands associated with the compromised network appliance to execute code 2 enterprise t1554 compromise host software binary phasejam has modified legitimate components to enable persistence and execution including inserting a web shell into getcomponent cgi and restauth cgi modifying dsupgrade pm to block system upgrades and overwriting remotedebug to execute arbitrary commands when specific parameters are provided 2 enterprise t1565 data manipulation phasejam has blocked legitimate upgrades of ivanti connect secure systems and falsely indicates a successful upgrade while operating on an older version 2 enterprise t1678 delay execution phasejam has used the sleep command within its code to generate a fake html upgrade progress bar that mimics a running process 2 enterprise t1140 deobfuscate decode files or information phasejam has the ability to decode base64 commands and data 2 enterprise t1685 disable or modify tools phasejam has modified ivanti connect secure appliances and blocks the system upgrades by altering the dsupgrade pm file 2 003 modify or spoof tool ui phasejam has prevented legitimate ivanti connect secure system upgrades by intercepting the upgrade command and rendering fake html upgrade progress bar through a function called processupgradedisplay which allowed the compromised device to remain under the control of the adversary 2 enterprise t1546 004 event triggered execution unix shell configuration modification phasejam has used a bash script to modify components on ivanti connect secure appliances and execute files via bin bash 1 it has also used the linux stream editor sed to execute commands 2 enterprise t1041 exfiltration over c2 channel phasejam has the ability to exfiltrate data from the victim appliance 2 enterprise t1105 ingress tool transfer phasejam has the ability to upload files onto the compromised appliance 2 enterprise t1036 003 masquerading rename legitimate utilities phasejam has renamed the file home bin remotedebug to remotedebug bak allowing the threats actors to write a malicious home bin remotedebug shell script 2 enterprise t1027 010 obfuscated files or information command obfuscation phasejam has encoded commands with base64 2 013 obfuscated files or information encrypted encoded file phasejam has launched a webshell using the mime base64 module that encoded and decoded base64 commands 2 enterprise t1505 003 server software component web shell phasejam has inserted perl based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance 2 enterprise t1489 service stop phasejam has disabled the cgi server process on ivanti connect secure appliances 2 references dragos 2026 march 24 dragos 2026 ot cybersecurity report year in review o g and petrochemicals focus retrieved april 17 2026 john wolfram josh murchie matt lin daniel ainsworth robert wallace dimiter andonov dhanesh kizhakkinan jacob thompson 2025 january 8 ivanti connect secure vpn targeted in new zero day exploitation retrieved april 14 2026 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 63 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-63


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 1 references to other resources (not html/xhtml )

 attack.mitre.org/software/S9014/S9014___.json  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/software/S9014
X-GitHub-Request-Id 48D2:DD21D:70384:74F5A:6A87419E
x-github-edge-region uksouth
Accept-Ranges bytes
Age 0
Date Thu, 20 Aug 2026 18:04:14 GMT
Via 1.1 varnish
X-Served-By cache-lcy-egml8630043-LCY
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787249055.518622,VS0,VE82
Vary Accept-Encoding
X-Fastly-Request-ID 86f974818de0f0159102cee1d104b14ee1c7aece
HTTP/2 301
server GitHub.com
content-type text/html
location htt????/attack.mitre.org/software/S9014/
access-control-allow-origin *
expires Thu, 20 Aug 2026 18:14:14 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 6788:2E92C9:71E6D:76A37:6A87419D
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Thu, 20 Aug 2026 18:04:14 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630054-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787249055.629160,VS0,VE86
vary Accept-Encoding
x-fastly-request-id d04f3552922424959ae3ee09a7d4a1e2adfc986a
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:19 GMT
access-control-allow-origin *
etag W/ 6a75ea93-e012
expires Thu, 20 Aug 2026 18:14:14 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 20E8:379822:7231F:76F56:6A87419E
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Thu, 20 Aug 2026 18:04:14 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630054-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787249055.723591,VS0,VE101
vary Accept-Encoding
x-fastly-request-id c272c067e625b0f74656940ba3753db98b0bbac5
content-length 8372

Meta Tags

title="PHASEJAM, Software S9014 | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size8372
load time (s)0.588142
redirect count2
speed download14238
server IP 185.199.108.153
* all occurrences of the string "http://" have been changed to "htt???/"