Mo' Shells Mo' Problems - Deep Panda Web Shells | CrowdStrike
ID: b0634c3a-9b75-4582-acb9-bdb83688fbb6
STIX ID: report--b0634c3a-9b75-4582-acb9-bdb83688fbb6
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2014-07-09
Last Modified Date: 2014-07-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
CrowdStrike's "Mo' Shells Mo' Problems" (Part 1) examines two web shells deployed by the China-linked APT Deep Panda: a minimal 28-byte ASP backdoor that executes VBScript from an HTTP parameter, and a robust ASP.NET (system_web.aspx) backdoor that uses covert authentication (cookies and specific HTTP headers), provides extensive file, SQL, Active Directory, and code-execution capabilities, and was used as a stealthy primary access vector; the report includes sample code, interface screenshots, command descriptions, and IOCs to aid detection and remediation.
