s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-asp.unidentified_001

📛 Threat Title

Malware family: Unidentified ASP 001 (Webshell)

Category: Unidentified ASP 001 (Webshell) First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `asp.unidentified_001`. Printable name: Unidentified ASP 001 (Webshell).

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server. [1] In addition to a ...

  • web:blog.securelayer7.net

    Learn about Web Shell attacks, their types, lifecycle, detection tools, and best prevention practices to secure servers from hidden threats.

  • web:blog.sucuri.net

    What is a web shell? Learn about the most common types, along with examples. We explain how shells work, what they do, and how to protect your site and clean up this malware from a hacked server.

  • web:cybersecuritynews.com

    This article explores the nature of webshells , their common attack vectors, advanced detection strategies, and a methodical approach to incident investigation and remediation . The Nature And Impact Of Webshells In CMS Platforms A webshell is essentially a script uploaded to a web server that allows an attacker to execute commands remotely.

  • web:github.com

    Guidance for mitigation web shells. #nsacyber. Contribute to nsacyber/Mitigating-Web-Shells development by creating an account on GitHub.

  • web:kudelskisecurity.com

    Persistent Exploitation of ASP .NET Components Fuels Remote Code Execution Attacks Context During a recent incident response engagement in June, our team observed an unattributed adversary exploiting a public-facing ASP .NET application, immediately followed by hands-on-keyboard activity.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Unidentified ASP 001 (Webshell) malware family including references, samples and yara signatures.

  • web:media.defense.gov

    Summary Cyber actors have increased the use of web shell malware for computer network exploitation [1][2][3][4]. Web shell malware is software deployed by a hacker, usually on a victim's web server. It can be used to execute arbitrary system commands, which are commonly sent over HTTP or HTTPS. Web shell attacks pose a serious risk to DoD components. Attackers often create web shells by ...

  • web:success.trendmicro.com

    A web shell is a piece of malicious code, often written in typical web development programming languages such as ASP , PHP and JSP, that attackers implant on web servers to provide remote access and code execution to server functions. To implant web shells, attackers take advantage of security gaps in Internet-facing web servers, typically vulnerabilities in web applications, for example CVE ...

  • web:www.microsoft.com

    To learn more about preventing trojans or other malware from affecting individual devices, read about preventing malware infection. Apply these mitigations to reduce the impact of this threat. Check the recommendations card for the deployment status of monitored mitigations .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.