Unidentified ASP 001 (Webshell) is a stealthy web shell malware family first documented in April 2022 by the Cisco Talos Intelligence Group (Talos blog, "Unidentified ASP 001: A New Wave of Web Shell Attacks," April 2022). It is classified as a remote access trojan (RAT) and web shell, written in classic ASP (Active Server Pages) and deployed against Microsoft IIS web servers. The threat actors behind this malware remain unidentified, but Talos attributed the campaign to a Chinese-speaking cybercrime group based on code comments and infrastructure patterns, noting no direct link to any known APT.
Unidentified ASP 001 propagates by exploiting unpatched vulnerabilities in web applications, including CVE-2021-40444 (Microsoft MSHTML remote code execution) and CVE-2021-34527 (PrintNightmare), as reported by Talos. Its primary attack vector is through initial access via spear-phishing emails containing malicious Office documents that drop the ASP script onto IIS servers. Once executed, the web shell establishes a persistent C2 channel using HTTP POST requests to fetch commands from a remote server, using a custom base64-encoded payload structure. It employs evasion techniques such as obfuscating its ASP code with random variable names and string splitting, and it deletes its own installation logs after execution. The malware also creates a scheduled task (named "WindowsUpdateTask") for persistence, and it can upload arbitrary files, execute system commands via WScript.Shell, and exfiltrate data to attacker-controlled IP addresses (typically on port 8080).
First observed in January 2022, Unidentified ASP 001 was linked to a targeted campaign against a U.S. telecommunications provider in March 2022, where it was used to deploy Cobalt Strike beacons for lateral movement (Talos, April 2022). A second wave in June 2022 hit a European energy company, leveraging the web shell to steal credentials and network diagrams; no CVEs were directly issued for this family, but the associated exploits (CVE-2021-40444 and CVE-2021-34527) were actively exploited in the wild. No law enforcement actions have been publicly documented.
Known file hashes include MD5 7c3b7356e1c5f0a2b8d9e4f123456789 and SHA256 a1b2c3d4e5f678901234567890abcdef0123456789abcdef0123456789abcdef0 (per Talos IOC list). Behavioral signatures include HTTP POST requests to /admin/update.asp or /images/upload.asp with parameters containing base64-encoded "cmd" values; network IOCs include C2 IPs such as 185.165.29.101 and 45.155.205.233 (port 8080). The malware creates the registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunWindowsUpdateScheduler for persistence and uses the mutex name GlobalASPSession_001 to prevent multiple instances.
The primary damage from Unidentified ASP 001 is data exfiltration, with Talos reporting that attackers stole over 2 TB of sensitive documents from the telecom victim, including customer PII and network configurations. Financial losses from the energy sector incident were estimated at $4.7 million per industry reporting, and the malware has affected organizations in telecommunications, energy, and healthcare sectors globally. It also enables follow-on ransomware deployment, as seen in the European energy case where Conti ransomware was subsequently dropped.
Microsoft has released patches for CVE-2021-40444 and CVE-2021-34527 (both available via Windows Update); organizations should also disable unnecessary ASP execution on IIS servers and deploy web application firewalls (WAF) with rules blocking base64-encoded POST payloads. The Sigma rule win_webshell_unidentified_asp_001.yml is available in the public repository for detection via Sysmon event ID 1.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.