404-Input-shell web shell - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 16:42:24 UTC Home > List all groups > List all tools > List all groups using tool 404-Input-shell web shell Tool: 404-Input-shell web shell Names 404-Input-shell web shell Category Malware Type Backdoor Description (Positive Technologies) The window for logging in to the web shell is disguised as a standard IIS 404 error page. To access the command line and run commands, the attacker must first enter the password. The field for entering the password is hidden: viewing it requires double-clicking the word Back. Information Last change to this tool card: 20 April 2020 Download this tool card in JSON format All groups using tool 404-Input-shell web shell Changed Name Country Observed APT groups TaskMasters 2010-May 2021 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fe60baf0-dbf4-4187-8b2f-8b93614af817 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fe60baf0-dbf4-4187-8b2f-8b93614af817 Page 1 of 1