test.aspx

Malware updated 6 months ago (2024-05-04T16:29:01.648Z)
Download STIX
Preview STIX
Test.aspx is a malicious software (malware) that was found embedded in a SharePoint server. It's part of a group of webshells, including stylecs.aspx and stylecss.aspx, all of which appear to be related to the China Chopper webshell. This malware can infiltrate your system through suspicious downloads, emails, or websites and once inside, it can steal personal information, disrupt operations, or even hold your data hostage for ransom. The test.aspx webshell operates by running base64 encoded JScript provided in the URL of the request, similar to its counterpart, stylecs.aspx. However, test.aspx has a unique feature where it uses a parameter related to the compromised organization to obtain the base64 encoded JScript. This allows it to execute specific actions and display certain information within the browser, based on the compromised organization's details. Interestingly, the test.aspx shell includes code that sets the HTTP response status to a 404 Not Found. This means that while an error page will be displayed to the user, the provided JScript will still run in the background. This clever disguise allows the malware to operate undetected, making it particularly dangerous as it continues to exploit and damage the compromised system without raising any immediate alarms.
Description last updated: 2023-10-10T18:29:25.952Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the test.aspx Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago