""ET TROJAN Possible STEADYPULSE Webshell Accessed M1""

SID: 2032801

Revision: 2

Class Type: attempted-user

Metadata: created_at 2021_04_21, updated_at 2021_04_21

Reference:

Protocol: tcp

Source Network: [$HOME_NET,$HTTP_SERVERS]

Source Port: $HTTP_PORTS

Destination Network: any

Destination Port: any

Flow: from_server,established

Contents:

  • Value: "200"

  • Value: "

    "

  • Value: "<input type=|22|text|22| name=|22|cmd|22| "

  • Value: "<input type=|22|text|22| name=|22|serverid|22| "

  • Value: ""

Within:

PCRE:

Special Options:

  • http_stat_code

  • file_data

source