ET MALWARE nginstaller PHP Webshell Command Execution Header (HTTP_NSC_CLIENTTYPE) Inbound

7.0.35.0SID: 2072323Rev: 1Enabled0 views
Sourceet/open
Fileemerging-malware.rules
CreatedOctober 2, 2026
UpdatedOctober 2, 2026
Classificationtrojan-activity
alert http any any -> $HOME_NET any (msg:"ET MALWARE nginstaller PHP Webshell Command Execution Header (HTTP_NSC_CLIENTTYPE) Inbound"; flow:established,to_server; http.header_names; to_lowercase; content:"http_nsc_clienttype|0d 0a|"; reference:url,cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances; classtype:trojan-activity; sid:2072323; rev:1; metadata:attack_target Server, created_at 2026_10_02, deployment Perimeter, confidence High, signature_severity Major, tag WebShell, updated_at 2026_10_02, mitre_tactic_id TA0003, mitre_tactic_name Persistence, mitre_technique_id T1505, mitre_technique_name Server_Software_Component;)

Metadata

attack targetServer
created at2026_10_02
deploymentPerimeter
confidenceHigh
signature severityMajor
tagWebShell
updated at2026_10_02
mitre tactic idTA0003
mitre tactic namePersistence
mitre technique idT1505
mitre technique nameServer_Software_Component

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!