China Chopper

China Chopper is a web shell which is approximately just 4 kilobytes in size, first discovered in 2012. This web shell is commonly used by malicious Chinese actors, including advanced persistent threat (APT) groups, to remotely control web servers. This web shell has two parts, the client interface (an executable file) and the receiver host file on the compromised web server.

China Chopper has many commands and control features such as a password brute-force attack option, code obfuscation, file and database management and a graphical user interface.[1][2][3][4] It originally was distributed from a website www.maicaidao.com which is now down. FireEye revealed that the client of this web shell is programmed in Microsoft Visual C++ 6.0

China Chopper was used in attacks against eight Australian web hosting providers, they were compromised due use of unsupported operating system (Windows Server 2008). Hackers connected the web servers to a Monero mining pool (a way by which cryptocurrency miners pool their resources), by which they mined about 3868 AUD worth of Monero.[5]

References

  1. "China Chopper". NJCCIC. Archived from the original on 13 January 2019. Retrieved 22 December 2018.
  2. "What is the China Chopper Webshell, and how to find it on a compromised system?". 28 March 2018. Archived from the original on 13 January 2019. Retrieved 22 December 2018.
  3. "Breaking Down the China Chopper Web Shell - Part I « Breaking Down the China Chopper Web Shell - Part I". FireEye. Archived from the original on 13 January 2019. Retrieved 22 December 2018.
  4. "Breaking Down the China Chopper Web Shell - Part II « Breaking Down the China Chopper Web Shell - Part II". FireEye. Archived from the original on 7 January 2019. Retrieved 22 December 2018.
  5. Stilgherrian. "Australian web hosts hit with a Manic Menagerie of malware". ZDNet. Archived from the original on 2019-01-31. Retrieved 2019-03-17.
This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.