RULE(RULE ID:322800)

Rule General Information
Release Date: 2019-07-17
Rule Name: R57 Webshell Attack Attempt -2
Severity:
CVE ID:
Rule Protection Details
Description: Webshell is a kind of web-based shell that can be uploaded to a web server to enable remote administration of the server. Hackers can use a webshell to access filesystem, database and execute commands or scripts. R57 is a kind of webshell that can scan the server for other webshell installations, with the option to remove or overwrite them.
Impact: Remote attackers may cause lots of damage to the system, including data theft, denial of service, etc.
Affected OS: Windows, Linux
Reference:
Solutions
Check web directory on the server and delete unknown files.