e45e329feb5d925b
下有如下特征:TxcWR1NNExZAD0ZaAWMIPAZjH1BFBFtHThcJSlUXWEd
解密出来是{"status":"c3VjY2Vzcw==","msg":"
另外:冰蝎管理webshell管理方式是,通过加载器加载post输入流中的恶意类实现的,这也是请求包很大的原因。
php
e45e329feb5d925b
eval
Decrypt(file_get_contents("php://input"))
jsp
this.getClass().getClassLoader()).g(Decrypt(bos.toByteArray())).newInstance().equals(pageContext)
equals(pageContext)
e45e329feb5d925b
aspx
e45e329feb5d925b
System.Text.Encoding.UTF8.GetBytes(Convert.ToBase64String(aes.CreateEncryptor().TransformFinalBlock(data, 0, data.Length)));
0x53,0x79,0x73,0x74,0x65,0x6d,0x2e,0x52,0x65,0x66,0x6c,0x65,0x63,0x74,0x69,0x6f,0x6e,0x2e,0x41,0x73,0x73,0x65,0x6d,0x62,0x6c,0x79