Sharp4RemoveLog is an anti-forensic tool used by the threat actor UAT-8099 during intrusions targeting unsecured or unpatched Microsoft IIS servers across Asia, particularly in Thailand and Vietnam. In the reported campaigns, attackers gained initial access by injecting web shells into vulnerable IIS servers, executed PowerShell, deployed GotoHTTP for persistence, and delivered BadIIS variants used for SEO fraud and redirection to fake gambling sites. Within this intrusion set, Sharp4RemoveLog was specifically used to erase Windows event logs to reduce detection and remove evidence of attacker activity. It was observed alongside other stealth and evasion tooling including OpenArk64 and CnCrypt Protect. The activity has been noted to overlap with the previously reported WEBJACK operation based on shared malware signatures, command-and-control infrastructure, and victimology.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used to remove/clear logs to reduce forensic visibility during operations.
Anti-forensic utility used to delete/clear Windows Event Logs to hinder detection and incident response.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.