Statistical Report on Malware Targeting Windows Web Servers in Q3 2024
| Overview Statistics 1. Status of Attacks Against Windows Web Servers 2. Categorization of Malware Used in Attacks 2.1. Privilege Escalation Tools 2.2. Hacking Tools 2.3. Backdoor 2.4. CoinMiner 3. Statistics on Web Shells Used in Attacks 3.1. Web Shell Statistics 4. Cases of Attacks in Q3 2024 Conclusion |
Overview
AhnLab SEcurity intelligence Center (ASEC) uses the AhnLab Smart Defense (ASD) infrastructure to respond to and classify attacks on poorly managed Windows web servers. This report covers the current state of damage to Windows web servers which had become the target of attacks based on the logs identified in the third quarter of 2024 and also discusses statistics on the attacks targeting said servers. Furthermore, malware used in each attack will be categorized with a summary of the statistical details.
Statistics
1. Status of Attacks on Windows Web Servers
The following are statistics on attacks against Windows web servers identified through AhnLab’s ASD logs in the third quarter of 2024.

Figure 1. Attacks against Windows web servers in Q3, 2024