{"id":1504,"date":"2024-02-20T10:37:40","date_gmt":"2024-02-20T10:37:40","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1504"},"modified":"2024-04-22T12:48:53","modified_gmt":"2024-04-22T12:48:53","slug":"hacktool-win32-aspxspy","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/02\/20\/hacktool-win32-aspxspy\/","title":{"rendered":"HackTool.Win32.ASPXSpy"},"content":{"rendered":"<h2 style=\"text-align: justify\">Overview<\/h2>\n<p style=\"text-align: justify\"><strong>Type:<\/strong> Hacktool<br \/>\n<strong>Destruction Level:<\/strong> High<br \/>\n<strong>Prevalence:<\/strong> Low<\/p>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify\">Malware name(s)<\/h3>\n<ul style=\"text-align: justify\">\n<li>HackTool.Win32.ASPXSpy (Padvish)<\/li>\n<li>HackTool.Win32.ASPXSpy (Eset)<\/li>\n<li>Backdoor:MSIL\/AspxSpy.A (Microsoft)<\/li>\n<\/ul>\n<h3><\/h3>\n<h3 style=\"text-align: justify\">What is a hackTool?<\/h3>\n<p style=\"text-align: justify\">Hacktools are tools designed to facilitate intrusion. These tools can be used by an intruder to recieve data from the victim organization\u2019s network. These tools are commonly used to retrieve the credentials of sensitive victim servers. For example, an intruder can use hacktools to guess passwords based on Brute Force attacks. In some cases, to escalate access levels and exploit existing vulnerabilities, HackTools are used. In general, hack tools can crash the computer and network security barriers and provide various capabilities to infiltrate systems.<\/p>\n<h3><\/h3>\n<h3 style=\"text-align: justify\">What is ASPXSpy malware?<\/h3>\n<p style=\"text-align: justify\">ASPXSpy is a web-based hack tool written in the ASPX programming language. It has been developed and is accessible as open-source on the Internet. Once installed on the victim&#8217;s servers, this tool enables the attacker to retrieve the victim&#8217;s server specifications, conduct port scanning operations, manipulate the victim&#8217;s file system, registry, and database, and execute command-line CMD as desired by the attacker.<\/p>\n<p>&nbsp;<\/p>\n<h2 style=\"text-align: justify\">Technical review<\/h2>\n<p>&nbsp;<\/p>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<p style=\"text-align: justify\">The signs of infection (or IoCs) can vary based on the commands received from the attacker.<\/p>\n<h3><\/h3>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify\">Performance description<\/h3>\n<p style=\"text-align: justify\">This tool initially receives the password from the attacker through the following login form and subsequently grants attacker, access to the implemented functionalities. In the provided examples, the password is the string &#8220;admin&#8221;.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3922\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/1-\u0634\u0631\u062d-\u0639\u0645\u0644\u06a9\u0631\u062f.png\" alt=\"AspxSpy \u0634\u0631\u062d \u0639\u0645\u0644\u06a9\u0631\u062f\" width=\"1219\" height=\"211\" \/>? The image below presents an example of the features of this tool<\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3923 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/2-\u0627\u0645\u06a9\u0627\u0646\u0627\u062a-\u0627\u0628\u0632\u0627\u0631.png\" alt=\" \u0627\u0645\u06a9\u0627\u0646\u0627\u062a \u0627\u0628\u0632\u0627\u0631 AspxSpy\" width=\"1263\" height=\"298\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>?As shown in the image above, the ASPXSpy penetration tool provides various features and capabilities to the attacker, which are described in the table below:<\/p>\n<table style=\"border-collapse: collapse;width: 95.8617%;height: 530px\" border=\"1\">\n<tbody>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><strong>Feature<\/strong><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: center\"><strong>Description<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>File Manager<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Provides the ability to manage the file system of the victim&#8217;s server, including deleting, creating, editing, renaming, copying, changing file timestamps, and downloading\/uploading files.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>File Search<\/em> <\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Enables searching and modifying the content of any file on the victim&#8217;s server.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>CmdShell<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Allows execution of command-line cmds specified by the attacker using cmd.exe, with the output sent back to the attacker.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>IIS Spy<\/em> <\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Displays the web server details, including usernames and passwords, extracting items such as the web server name, domain name, IP address, and port number assigned to the web server.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>Process<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Displays the list of the system&#8217;s current processes, including the process name, ID, number of threads, execution priority, and the ability to terminate them.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>Services<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Displays the list of services registered in the system, including the name, corresponding process ID, path of the executable file, current state of the service, and its start state<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>UserInfo<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Displays system users and their details.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>SysInfo<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Displays system information, including OS information, hardware specifications, information about installed drivers, and MAC address(es).<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>RegShell<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Allows access to the victim server&#8217;s registry, enabling the viewing, deletion, creation, and editing of registry keys.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>PortScan<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Enables scanning of desired ports on the current server or external servers.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>DataBase<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Provides the ability to connect and execute queries for MSSQL and OleDb databases.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>PortMap<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">\u00a0Facilitates Port Forwarding operations, mapping remote connections to IP addresses and local ports.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>WmiTools<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Allows connection to the namespaces of the victim server and execution of WMI queries.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>PluginLoader<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Uploads a file into the current processor memory.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 16.8192%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>ADSViewer<\/em><\/strong><\/span><\/td>\n<td style=\"width: 110.375%;height: 24px;text-align: left\">Enables viewing of the active directory of the victim server along with their features and subdirectories.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>?In the image below, the code related to the PluginLoader feature is presented in a sample of this malware.<\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-3924 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/3-\u06a9\u062f-\u0645\u0631\u0628\u0648\u0637-\u0628\u0647-\u0642\u0627\u0628\u0644\u06cc\u062a-PluginLoader-\u0628\u062f\u0627\u0641\u0632\u0627\u0631.png\" alt=\"\u06a9\u062f \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 \u0642\u0627\u0628\u0644\u06cc\u062a PluginLoader \u0628\u062f\u0627\u0641\u0632\u0627\u0631\" width=\"1565\" height=\"611\" \/><\/p>\n<h2><\/h2>\n<p>&nbsp;<\/p>\n<h2 style=\"text-align: justify\">How to deal with and clean the system?<\/h2>\n<p style=\"text-align: justify\">Padvish antivirus can detect this malware and remove it from the system. It is also recommended to regularly update your operating system and antivirus software.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Hacktool Destruction Level: High Prevalence: Low &nbsp; Malware name(s) HackTool.Win32.ASPXSpy (Padvish) HackTool.Win32.ASPXSpy (Eset) Backdoor:MSIL\/AspxSpy.A (Microsoft) What is a hackTool? Hacktools are tools designed to facilitate intrusion. These tools can be used by an intruder to recieve data from the victim organization\u2019s network. These tools are commonly used to retrieve the credentials of sensitive&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[47,48],"tags":[54,55,56,57],"class_list":["post-1504","post","type-post","status-publish","format-standard","hentry","category-malware","category-hacktool","tag-aspx","tag-aspxspy","tag-hacktool","tag-hacktool-win32-aspxspy"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1504"}],"version-history":[{"count":10,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1504\/revisions"}],"predecessor-version":[{"id":1542,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1504\/revisions\/1542"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1504"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1504"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}