MALWARE-BACKDOOR -- Snort has detected suspicious communication traffic unrelated to commands, such as exfiltration of data from the infected machine, especially larger chunks of data.
MALWARE-BACKDOOR Asp.Backdoor.MoveITShell connection attempt
This rule looks for webshell client connection attempts that are associated with the MOVEit vulnerability from June, 2023.
THis rule is triggered when an attacker attempts to connect to a webshell.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
No rule groups
None
No information provided
None