Suspicious 75% Download

94a0e2585945b2dd1263d360d85405e2bf16186ac56bbd5c3a35a02128b732f1.unknown

ASP webshell giving SQL access. Might also be a dual use tool.Creates DOM element
SHA-25694a0e2585945b2dd1263d360d85405e2bf16186ac56bbd5c3a35a02128b732f1

Evidence

ASP webshell giving SQL access. Might also be a dual use tool. lines 1–16
1<%@ Page Language="C#" trace="false" EnableViewStateMac="false" validateRequest="false" enableEventValidation="false" %>
2<%@ import Namespace="System.Collections.Generic"%>
3<%@ import Namespace="System.Web.Services"%>
4<%@ import Namespace="System.Web"%>
5<%@ import Namespace="System.IO"%>
6<%@ import Namespace="System"%>
7<%@ import Namespace="System.Net" %>
8<%@ import Namespace="System.Diagnostics"%>
9<%@ Import Namespace="System.Data.SqlClient"%>
10<%@ import Namespace="Microsoft.Win32"%>
11<%@ import Namespace="System.Management"%>
⋯5 lines
Matches 'HttpContexts' lines 237–243
237:2… }
238 msgs.Text = "";
239
240 if (Request.QueryString["Name"] != null || Request.QueryString["Name"] != "")
241 {
242 string temp = Request.QueryString["Name"];
243 …
Reads an ASP.NET request parameter lines 263–270
263:13… IsPostBack)
264 {
265
266 string evarg = Request["__EVENTTARGET"];
267 string args = Request["__ARGS"];
268
269 // Page.Title = evarg;
270 if …
.NET FromBase64String method reference lines 536–540
536:50… der.GetDecoder();
537
538 byte[] todecode_byte = Convert.FromBase64String(data);
539 int charCount = utf8Decode.GetCharCount(todecode_byte, 0, todecode_byte.Length);
540 char[] decode …
ASP.NET Response.Write response sink lines 878–883
878:13… Page.Response.ContentType = "application/unknown";
879 Response.WriteFile(fs.FullName);
880 Page.Response.Flush();
881 Page.Response.Close();
882 Response.End();
883 …

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.