RULE(RULE ID:322807)

Rule General Information
Release Date: 2019-07-17
Rule Name: PhpSpy_2013 Webshell Database Attack Attempt -2
Rule Protection Details
Description: A webshell is a web-based shell that can be uploaded to a web server to enable remote administration of the server. Hackers can use a webshell to access filesystem, database and execute commands or scripts. PhpSpy is a popular webshell as a backdoor of the infected server.
Impact: Remote attackers may cause lots of damage to the system, including data theft, denial of service, etc.
Affected OS: Windows, Linux
Check web directory on the server and delete unknown files.