alert http $HTTP_SERVERS any -> $EXTERNAL_NET any (
msg:"ET MALWARE Possible Outbound WebShell JPEG";
flow:established,from_server;
http.stat_code;
content:"200";
file.data;
content:"|FF D8 FF E0|"; depth:4;
content:"JFIF"; distance:2; within:4;
content:"<%eval|20|request|28 22|"; distance:0; fast_pattern;
classtype:trojan-activity;
sid:2027739; rev:3;
metadata:attack_target Web_Server, created_at 2019_07_22, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag WebShell, updated_at 2020_09_14;
)