ET WEB_SERVER Generic Webshell Activity (Response)
Sourceet/open
CreatedApril 10, 2023
UpdatedApril 10, 2023
Classificationweb-application-attack
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET WEB_SERVER Generic Webshell Activity (Response)"; flow:established,to_client; file.data; content:"<body><title>FILE MANAGER v.1.0</title>"; content:"<h1>Green Dinosaur</h1>"; fast_pattern; content:"|61 63 74 69 6f 6e 3d 27 3f 66 70 61 74 68 3d|"; distance:0; reference:md5,9cdda333432f403b408b9fe717163861; classtype:web-application-attack; sid:2044914; rev:1; metadata:attack_target Web_Server, created_at 2023_04_10, deployment Perimeter, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_04_10; target:src_ip;)
References
| md5 | 9cdda333432f403b408b9fe717163861 |
Metadata
attack targetWeb_Server
created at2023_04_10
deploymentPerimeter
confidenceHigh
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2023_04_10
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!