""ET WEB_SERVER WebShell Generic eval of gzinflate""

SID: 2017400

Revision: 6

Class Type: trojan-activity

Metadata: created_at 2013_08_31, updated_at 2013_08_31

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HTTP_SERVERS

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "gzinflate"

  • Value: "eval"

Within:

PCRE: "/^[\r\n\s]?\x28[\r\n\s]?gzinflate/Rsi"

Special Options:

  • file_data

  • nocase

  • nocase

source