Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware ASPXSpy

ASPXSpy

TLP:CLEAR
Family

Also known as: ASPXTool

AI Analysis

· 2 days ago

Executive Summary

ASPXTool is an advanced ASP.NET web shell refined by Threat Group‑3390 to provide attackers with persistent, remote control over compromised Windows web servers. It leverages obfuscation and standard web protocols to evade detection while enabling file uploads, command execution, and lateral movement. The presence of this shell indicates a successful compromise of the web application layer and may enable exfiltration or further network intrusion.

Enhanced Description

ASPXSpy is a web shell written in ASP.NET that grants attackers command and control capabilities over compromised web servers. The code base was originally released as the generic ASPXSpy template, but Threat Group‑3390 has modified it to create the variant known as ASPXTool. Once installed on a vulnerable Windows web application, the shell exposes an HTTP endpoint that accepts encrypted commands or file uploads via standard form posts. Attackers can remotely execute PowerShell scripts, spawn command shells, upload arbitrary binaries, delete logs, and manipulate web server configuration files to maintain persistence. The modified ASPXTool adds additional stealth mechanisms — such as obfuscated filenames, use of innocuous .aspx extensions, and dynamic code compilation – that lower the likelihood of detection by signature‑based scanners. By operating directly within the trusted web application context, it can bypass many host‑based security controls and facilitate lateral movement to internal hosts over SMB or RDP. Impact assessment shows that a compromised web server can become an entry point for data exfiltration, credential harvesting, or full pivoting into enterprise networks. Organizations hosting .NET applications should enforce strict input validation, restrict file upload permissions, and monitor anomalous HTTP traffic for signs of shell usage.

Key Capabilities

  • Remote code execution via HTTP endpoint
  • File upload/download capability
  • PowerShell script spawning
  • Registry or configuration modification for persistence
  • Stealthy operations using obfuscated .aspx files

ATT&CK Techniques

T1071.001
T1059.003
T1104
T1086
T1112

Recommended Actions

  • Conduct thorough file integrity monitoring on all web server directories, especially under App_Data and bin folders Ensure that only authorized users can write to the ASP.NET runtime directory Deploy web application firewall (WAF) rules to block suspicious form POST payloads containing encoded commands Perform regular scans of .aspx and related files for known shell signatures or unknown binaries Implement strict monitoring of SMB/RDP traffic originating from compromised web servers
  • Disable remote upload features unless explicitly required by the business process
  • Apply the latest Windows patches, particularly addressing web server vulnerabilities Educate developers on secure coding practices to reduce injection surface

Suggested Tags

web-shell
asp.net
threat-group-3390
data-exfiltration
remote-command
persistence

Confidence Assessment

The assessment is based solely on limited public statements about ASPXSpy and its modification into ASPXTool by Threat Group‑3390. Key technical details such as command sets, persistence mechanisms, and C2 infrastructure are not provided, resulting in a low confidence level regarding operational specifics. Additional dynamic analysis and forensic data would be required to validate the exact capabilities and impact.

Description

ASPXSpy is a Web shell. It has been modified by Threat Group-3390 actors to create the ASPXTool version. (Citation: Dell TG-3390)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.