ET WEB_SERVER Generic Webshell Observed Outbound
Sourceet/open
CreatedFebruary 23, 2021
UpdatedFebruary 23, 2021
Classificationattempted-admin
alert http $HTTP_SERVERS any -> $EXTERNAL_NET any (msg:"ET WEB_SERVER Generic Webshell Observed Outbound"; flow:established,to_client; http.stat_code; content:"200"; file.data; content:"<form action=|22 22 20|"; content:"<input|20|type=|22|text|22 20|name=|22|_jy|22|><input|20|type=|22|submit|22 20|value=|22|>>"; fast_pattern; classtype:attempted-admin; sid:2031651; rev:1; metadata:attack_target Web_Server, created_at 2021_02_23, deployment Perimeter, deployment SSLDecrypt, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_02_23;)
Metadata
attack targetWeb_Server
created at2021_02_23
deploymentSSLDecrypt
confidenceMedium
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2021_02_23
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!