RULE(RULE ID:322808)

Rule General Information
Release Date: 2019-07-17
Rule Name: PhpSpy_2011 Webshell Attack Attempt -1
Severity:
CVE ID:
Rule Protection Details
Description: Webshell is a kind of web-based shell that can be uploaded to a web server to enable remote administration of the server. Hackers can use a webshell to access filesystem, database and execute commands or scripts. PhpSpy is a popular webshell as a backdoor of the infected server.
Impact: Remote attackers may cause lots of damage to the system, including data theft, denial of service, etc.
Affected OS: Windows, Linux
Reference:
Solutions
Check web directory on the server and delete unknown files.