Which TWO of the following are indicators of a webshell attack found in web server logs? (Select TWO)
Webshells are often coded in dynamic script languages and expose command execution through parameters such as cmd, exec, or command. A request to a .asp or .php file that includes these parameter names strongly suggests an attacker is attempting to pass shell commands to the server. Such parameter names are unnatural for legitimate application workflows, making this a highly specific webshell indicator.
Why this answer
Option C is correct because webshells are typically small scripts (e.g., .asp, .php, .jsp) that accept command parameters such as cmd, exec, or shell, so log entries showing requests to such files with those parameter names are a strong indicator of command execution through a webshell. Option E is correct because attackers commonly upload a webshell into a writable upload directory and then interact with it via POST requests, so repeated POSTs to a script in an upload folder in the web logs is a classic webshell traffic pattern. Option A is not specific to webshells, since OPTIONS and TRACE are legitimate HTTP methods and their presence alone does not indicate a webshell.
Option B is too generic, as high traffic from one IP can result from many benign causes such as crawlers, load balancers, or DoS activity. Option D is also non-specific, because frequent 404 errors usually indicate broken links, scanning, or enumeration rather than webshell command execution.
Exam trap
EC-Council often tests the distinction between generic web anomalies (like high traffic or 404 errors) and webshell-specific indicators (like command parameters in script requests), so candidates mistakenly select broad traffic patterns instead of the precise log entries that reveal command execution.