This detection identifies the deployment of a malicious “Antichat Shell v1.3.php” web shell, indicating an adversary has established a persistent backdoor on a web server to facilitate remote command execution and data exfiltration. A proactive hunt is essential in Azure Sentinel to rapidly isolate compromised endpoints and prevent lateral movement before attackers can leverage this foothold for deeper network reconnaissance or credential theft.
rule webshell_Antichat_Shell_v1_3_2 {
meta:
description = "Web Shell - file Antichat Shell v1.3.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "40d0abceba125868be7f3f990f031521"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s3 = "$header='<html><head><title>'.getenv(\"HTTP_HOST\").' - Antichat Shell</title><m"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file Antichat Shell v1.3.php detection rule, along with suggested filters and exclusions:
Scenario: Legitimate Deployment via CI/CD Pipeline
Antichat) during nightly builds. The pipeline explicitly uploads v1.3.php to the web root directory as part of a standard release process, mimicking a manual file upload often associated with web shell creation.10.20.30.0/24) or where the HTTP User-Agent string contains specific identifiers like GitHub-Hookshot or Jenkins.Scenario: Scheduled Backup and Restoration Job
Antichat Shell v1.3.php file to ensure consistency with the backup image. This scheduled task triggers the rule because it involves writing a PHP file to the web server’s document root at a fixed time (e.g., 02:00 AM).vbrservice.exe (Veeam) or cron running under the backup_admin account.