Steganographic webshell with ONEPIECE marker embedded in image-masquerading file

This rule detects potential web shells that employ steganographic techniques by embedding malicious executable script code within image file structures (JPG or PNG). It specifically flags files containing common web shell markers 'ONEPIECE' or 'x_best_911' in combination with embedded script tags (e.g., <script, eval, <%, <?php) within files identified as having image magic bytes.