SessionManager
- First seen
- 2022-03-01 00:00:00
- Malware type
- webshell, trojan
- Profile updated
- 2026-07-07 15:11:53
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
A malicious IIS module that allows up/download of files, remote command execution, and using the compromised server as a hop into the network behind.
Detection coverage
- 1 YARA rules
Detection rules
- SEKOIA_Apt_Unknown_Sessionmanageriis_Strings (yara-rule)
Reports & references
- Kaspersky — 106868 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Session Manager (report)