""ET WEB_SERVER WSO WebShell Activity POST structure 2""

SID: 2016354

Revision: 2

Class Type: attempted-user

Metadata: created_at 2013_02_05, updated_at 2013_02_05

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "POST"

  • Value: " name=|22|c|22|"

  • Value: "name=|22|p1|22|"

Within:

PCRE: "/name=(?P[\x22\x27])a(?P=q)[^\r\n]*\r\n[\r\n\s]+(?:S(?:e(?:lfRemove|cInfo)|tringTools|afeMode|ql)|(?:Bruteforc|Consol)e|FilesMan|Network|Logout|Php)/Pi"

Special Options:

  • http_method

  • http_client_body

  • http_client_body

  • fast_pattern

source