TF-MAL-php.aspxspy
📛 Threat Title
Malware family: ASPXSpy
Description
ThreatFox malware family `php.aspxspy`. Printable name: ASPXSpy.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
php.aspxspy
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/php.aspxspy
IOC database
- Type
- domain
- Value
php.aspxspy- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-php.aspxspy
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/php.aspxspy
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.cloudfall.cn
ASPXSpy is a Web shell. It has been modified by Threat Group-3390 actors to create the ASPXTool version. [1] ID: S0073 ⓘ Associated Software: ASPXTool ⓘ Type: MALWARE ⓘ Platforms: Windows Version: 1.1 Created: 31 May 2017 Last Modified: 30 March 2020 ATT&CK® Navigator Layers Techniques Used Domain ID Name Use Enterprise T1505 .003 Server Software Component: Web Shell
-
web:attack.mitre.org
ASPXSpy is a Web shell. It has been modified by Threat Group-3390 actors to create the ASPXTool version. [1]
-
web:bazaar.abuse.ch
Malware samples associated with tag ASPXSpy MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with ASPXSpy . Database Entry
-
web:cyber-kill-chain.ch
ASPXSpy is a Web shell. It has been modified by Threat Group-3390 actors to create the ASPXTool version. [1]
-
web:docs.sophos.com
This page explains the names we use for malicious behavior detected on computers or servers.
-
web:github.com
This is a webshell open source project. Contribute to tennc/webshell development by creating an account on GitHub.
-
web:malpedia.caad.fkie.fraunhofer.de
ASPXSpy is an open-source web shell written in C# that allows a threat actor to accomplish various post-exploitation tasks, including file access and command execution.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.cybermaterial.com
ASPXSpy is a type of web shell commonly used by advanced threat actors to maintain unauthorized access to compromised systems. This malware targets web servers, particularly those running Internet Information Services (IIS), a popular server software from Microsoft. ASPXSpy allows attackers to execute arbitrary commands on infected machines, making it a valuable tool for cybercriminals looking ...
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.