Hostile 92% Download

19f00c273bc6a5e5874b8f0927c5f06e2b56669f183ff33c3cb35d728e3375c0.unknown

ASP webshell with SQL access

ASP webshell giving SQL access. Might also be a dual use tool.Creates DOM element
SHA-25619f00c273bc6a5e5874b8f0927c5f06e2b56669f183ff33c3cb35d728e3375c0

Evidence

ASP webshell giving SQL access. Might also be a dual use tool. lines 1–16
1<%@ Page Language="C#" trace="false" EnableViewStateMac="false" validateRequest="false" enableEventValidation="false" %>
2<%@ import Namespace="System.Collections.Generic"%>
3<%@ import Namespace="System.Web.Services"%>
4<%@ import Namespace="System.Web"%>
5<%@ import Namespace="System.IO"%>
6<%@ import Namespace="System"%>
7<%@ import Namespace="System.Net" %>
8<%@ import Namespace="System.Diagnostics"%>
9<%@ Import Namespace="System.Data.SqlClient"%>
10<%@ import Namespace="Microsoft.Win32"%>
11<%@ import Namespace="System.Management"%>
⋯5 lines
Matches 'HttpContexts' lines 239–245
239:2… }
240 msgs.Text = "";
241
242 if (Request.QueryString["Name"] != null || Request.QueryString["Name"] != "")
243 {
244 string temp = Request.QueryString["Name"];
245 …
Reads an ASP.NET request parameter lines 265–272
265:13… IsPostBack)
266 {
267
268 string evarg = Request["__EVENTTARGET"];
269 string args = Request["__ARGS"];
270
271 // Page.Title = evarg;
272 if …
.NET FromBase64String method reference lines 538–542
538:50… der.GetDecoder();
539
540 byte[] todecode_byte = Convert.FromBase64String(data);
541 int charCount = utf8Decode.GetCharCount(todecode_byte, 0, todecode_byte.Length);
542 char[] decode …
ASP.NET Response.Write response sink lines 880–885
880:13… Page.Response.ContentType = "application/unknown";
881 Response.WriteFile(fs.FullName);
882 Page.Response.Flush();
883 Page.Response.Close();
884 Response.End();
885 …

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.