ET WEB_SERVER Generic PHP Webshell Activity

SID: 2048557Rev: 159 views
History
Sourceet/open
CreatedOctober 13, 2023
UpdatedOctober 13, 2023
Classificationtrojan-activity
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET WEB_SERVER Generic PHP Webshell Activity"; flow:established,to_client; file.data; content:"/home/aravalcl/public_html/"; fast_pattern; content:"ob_start|28 29|"; content:">Command</a>>"; content:"Software|3a|"; reference:md5,f899d6cbe1be6395a0fa2a802b8eb579; classtype:trojan-activity; sid:2048557; rev:1; metadata:attack_target Web_Server, created_at 2023_10_13, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_10_13, reviewed_at 2023_10_13; target:src_ip;)

References

md5
f899d6cbe1be6395a0fa2a802b8eb579

Metadata

attack targetWeb_Server
created at2023_10_13
deploymentPerimeter
performance impactLow
confidenceHigh
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2023_10_13
reviewed at2023_10_13

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!