""ET WEB_SERVER Generic Webshell Activity (POST)""
SID: 2048923
Revision: 1
Class Type: web-application-attack
Metadata: attack_target Web_Server, created_at 2023_10_27, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Critical, updated_at 2023_10_27, reviewed_at 2023_10_27
Reference:
-
md5
-
eda02ae6dd7d0fe841653f5e6a69d17e
Protocol: tcp
Source Network: $HOME_NET
Source Port: $HTTP_PORTS
Destination Network: any
Destination Port: any
Flow: established,to_client
Contents:
-
Value: "
<meta http-equiv=|27|Content-Type|27 20|content=|27|text/html" -
Value: "charset="
-
Value: ">
" -
Value: "|20|-|20|WSO|20|"
Within: 50
PCRE:
Special Options:
-
file_data
-
fast_pattern