al0ne / suricata-rules

Suricata IDS rules 用来检测红队渗透/恶意行为等,支持检测CobaltStrike/MSF/Empire/DNS隧道/Weevely/菜刀/冰蝎/挖矿/反弹shell/ICMP隧道等

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

False positive? 3016006

alternativesurfer opened this issue · comments

I am receiving an alert on: 3016006 from an iPhone on my network.
Is this a false positive?

10/30/2019-09:05:10.232851 [] [1:3016006:1] Weevely PHP Backdoor Response [] [Classification: Executable Code was Detected] [Priority: 1] {TCP} 70.186.27.16:80 -> 192.XXX.XXX.XXX:40060

commented

Please write down the complete request body and response body