ET MALWARE nginstaller PHP Webshell Command Execution Header (HTTP_NSC_LDAP) Inbound
Sourceet/open
Fileemerging-malware.rules
CreatedOctober 2, 2026
UpdatedOctober 2, 2026
Classificationtrojan-activity
alert http any any -> $HOME_NET any (msg:"ET MALWARE nginstaller PHP Webshell Command Execution Header (HTTP_NSC_LDAP) Inbound"; flow:established,to_server ; http.header_names; to_lowercase; content:"http_nsc_ldap|0d 0a|"; reference:url,cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances ; classtype:trojan-activity; sid:2072322; rev:1; metadata:attack_target Server, created_at 2026_10_02, deployment Perimeter, confidence High, signature_severity Major, tag WebShell, updated_at 2026_10_02, mitre_tactic_id TA0003, mitre_tactic_name Persistence, mitre_technique_id T1505, mitre_technique_name Server_Software_Component;)
Metadata
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!