""ET TROJAN Possible STEADYPULSE Webshell Accessed M2""

SID: 2032800

Revision: 2

Class Type: attempted-user

Metadata: created_at 2021_04_21, updated_at 2021_04_21

Reference:

Protocol: tcp

Source Network: [$HOME_NET,$HTTP_SERVERS]

Source Port: $HTTP_PORTS

Destination Network: any

Destination Port: any

Flow: from_server,established

Contents:

  • Value: "200"

  • Value: "|0d 0a|Results of|20 27|"

  • Value: "|27 20|execution|3a 0a 0a|"

Within: 256

PCRE:

Special Options:

  • http_stat_code

  • file_data

  • fast_pattern

source