Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

China Chopper

From Wikipedia, the free encyclopedia
Web shell

China Chopper is aweb shell approximately 4kilobytes in size, first discovered in 2012. This web shell is commonly used by malicious Chinese actors, includingadvanced persistent threat (APT) groups, to remotely controlweb servers. This web shell has two parts, the client interface (anexecutable file) and the receiver host file on the compromised web server.

China Chopper has many commands and control features such as a passwordbrute-force attack option,code obfuscation, file anddatabase management and agraphical user interface.[1][2][3][4] It originally was distributed from a website www.maicaidao.com which is now down.FireEye revealed that the client of this web shell is programmed inMicrosoft Visual C++ 6.0

China Chopper was used in attacks against eight Australianweb hosting providers which were compromised due to their use of an unsupported operating system (Windows Server 2008).Hackers connected the web servers to aMoneromining pool, by which they mined about 3868 AUD worth of Monero.[5]

In 2021, a version of the web shell programmed inJScript was used byAdvanced Persistent Threat groupHafnium to exploit fourzero-day vulnerabilities inMicrosoft Exchange Server, in the2021 Microsoft Exchange Server data breach. This web shell was dropped when one of these vulnerabilities was exploited, allowing attackers to upload a program which ran with administratorprivileges.[6] With only the address of the.aspx file containing the script, aHTTP POST request could be made to the script with just a command in the request, causing the script to execute the command immediately using the JScript 'eval' function, allowing attackers to run arbitrary code on the server.[7]

References

[edit]
  1. ^"China Chopper".NJCCIC.Archived from the original on 13 January 2019. Retrieved22 December 2018.
  2. ^"What is the China Chopper Webshell, and how to find it on a compromised system?". 28 March 2018.Archived from the original on 13 January 2019. Retrieved22 December 2018.
  3. ^"Breaking Down the China Chopper Web Shell - Part I « Breaking Down the China Chopper Web Shell - Part I".Mandiant.Archived from the original on 13 January 2019. Retrieved2022-01-03.
  4. ^"Breaking Down the China Chopper Web Shell - Part II « Breaking Down the China Chopper Web Shell - Part II".Mandiant.Archived from the original on 7 January 2019. Retrieved2022-01-03.
  5. ^Stilgherrian."Australian web hosts hit with a Manic Menagerie of malware".ZDNet.Archived from the original on 2019-01-31. Retrieved2019-03-17.
  6. ^"ProxyLogon".ProxyLogon (in Chinese (Taiwan)). Retrieved2021-03-16.
  7. ^"Exchange Cyberattacks Escalate as Microsoft Rolls One-Click Fix".threatpost.com. 16 March 2021. Retrieved2021-03-16.
Stub icon

Thiscomputer security article is astub. You can help Wikipedia byadding missing information.

Retrieved from "https://en.wikipedia.org/w/index.php?title=China_Chopper&oldid=1200282081"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp