One Day Sec

What is HighShell and how does it work?

HighShell is an ASP.NET webshell targeting Windows servers, part of the APT34 leaked tools. It has a red login box requiring the password `Th!sN0tF0rFAN` to access, as detailed in Analysis of APT34 Leaked Tools - HighShell and HyperShell. After successful authentication, the login box turns green, granting control over the compromised server.
HighShellwebshellASP.NETAPT34Windows serverauthentication

Browse all Q&A →