logo

Mo' Shells Mo' Problems - Deep Panda Web Shells | CrowdStrike

ID: b0634c3a-9b75-4582-acb9-bdb83688fbb6

STIX ID: report--b0634c3a-9b75-4582-acb9-bdb83688fbb6

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2014-07-09

Last Modified Date: 2014-07-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
CrowdStrike's "Mo' Shells Mo' Problems" (Part 1) examines two web shells deployed by the China-linked APT Deep Panda: a minimal 28-byte ASP backdoor that executes VBScript from an HTTP parameter, and a robust ASP.NET (system_web.aspx) backdoor that uses covert authentication (cookies and specific HTTP headers), provides extensive file, SQL, Active Directory, and code-execution capabilities, and was used as a stealthy primary access vector; the report includes sample code, interface screenshots, command descriptions, and IOCs to aid detection and remediation.