GhostContainer App_Web_8c9b251fb5b3 proxy/socket-forward request via fakePath/fakePageName parameters on Exchange/OWA
This rule detects HTTP requests directed at Microsoft Exchange Outlook Web Access (OWA) that contain suspicious 'fakePath' and 'fakePageName' parameters in the URI. These parameters are indicators of the 'GhostContainer' malware attempting to establish a socket forwarding proxy through the web server to facilitate command and control communications.
Suricata

