HTML/Ace.C

description-logoAnalysis

The trojan is a set of HTML/ASP files providing a web interface to modify the filesystem of the compromised server, using ASP functions. To install it, one must first copy the files on the server. It means one must already have initial access the the server (the files can be thought of as a filesystem browser for ASP web servers).

  • The file "index.asp" is a login page.
  • "edir.asp" deletes or creates folders.
  • "edit.asp" deletes, creates or edits files.
  • "list.asp" shows a listing of the files and folders.
  • "upfile.asp" and "upfile.htm" work together to upload files and images.
  • "wb.htm" is used to change the current drive (it can jump to c:, d:, e:, etc.)

recommended-action-logoRecommended Action

    FortiGate Systems
  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

Telemetry logoTelemetry