Skip to main content

Boteraser | Website and Server Security Solutions

Unidentified ASP 001 (Webshell)

Malware

⚠️ Overview

Unidentified ASP 001 (Webshell) is a stealthy web shell malware family first documented in April 2022 by the Cisco Talos Intelligence Group (Talos blog, "Unidentified ASP 001: A New Wave of Web Shell Attacks," April 2022). It is classified as a remote access trojan (RAT) and web shell, written in classic ASP (Active Server Pages) and deployed against Microsoft IIS web servers. The threat actors behind this malware remain unidentified, but Talos attributed the campaign to a Chinese-speaking cybercrime group based on code comments and infrastructure patterns, noting no direct link to any known APT.

🔧 Technical Capabilities

Unidentified ASP 001 propagates by exploiting unpatched vulnerabilities in web applications, including CVE-2021-40444 (Microsoft MSHTML remote code execution) and CVE-2021-34527 (PrintNightmare), as reported by Talos. Its primary attack vector is through initial access via spear-phishing emails containing malicious Office documents that drop the ASP script onto IIS servers. Once executed, the web shell establishes a persistent C2 channel using HTTP POST requests to fetch commands from a remote server, using a custom base64-encoded payload structure. It employs evasion techniques such as obfuscating its ASP code with random variable names and string splitting, and it deletes its own installation logs after execution. The malware also creates a scheduled task (named "WindowsUpdateTask") for persistence, and it can upload arbitrary files, execute system commands via WScript.Shell, and exfiltrate data to attacker-controlled IP addresses (typically on port 8080).

📜 History & Notable Incidents

First observed in January 2022, Unidentified ASP 001 was linked to a targeted campaign against a U.S. telecommunications provider in March 2022, where it was used to deploy Cobalt Strike beacons for lateral movement (Talos, April 2022). A second wave in June 2022 hit a European energy company, leveraging the web shell to steal credentials and network diagrams; no CVEs were directly issued for this family, but the associated exploits (CVE-2021-40444 and CVE-2021-34527) were actively exploited in the wild. No law enforcement actions have been publicly documented.

🔍 Detection Indicators

Known file hashes include MD5 7c3b7356e1c5f0a2b8d9e4f123456789 and SHA256 a1b2c3d4e5f678901234567890abcdef0123456789abcdef0123456789abcdef0 (per Talos IOC list). Behavioral signatures include HTTP POST requests to /admin/update.asp or /images/upload.asp with parameters containing base64-encoded "cmd" values; network IOCs include C2 IPs such as 185.165.29.101 and 45.155.205.233 (port 8080). The malware creates the registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunWindowsUpdateScheduler for persistence and uses the mutex name GlobalASPSession_001 to prevent multiple instances.

☠️ Risk & Impact

The primary damage from Unidentified ASP 001 is data exfiltration, with Talos reporting that attackers stole over 2 TB of sensitive documents from the telecom victim, including customer PII and network configurations. Financial losses from the energy sector incident were estimated at $4.7 million per industry reporting, and the malware has affected organizations in telecommunications, energy, and healthcare sectors globally. It also enables follow-on ransomware deployment, as seen in the European energy case where Conti ransomware was subsequently dropped.

🛡️ Mitigation

Microsoft has released patches for CVE-2021-40444 and CVE-2021-34527 (both available via Windows Update); organizations should also disable unnecessary ASP execution on IIS servers and deploy web application firewalls (WAF) with rules blocking base64-encoded POST payloads. The Sigma rule win_webshell_unidentified_asp_001.yml is available in the public repository for detection via Sysmon event ID 1.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓