← Back to SOC feed Coverage →

Web Shell - file 404.asp

yara HIGH signature-base
florian-rothwebshell
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at signature-base →
Retrieved: 2026-08-08T23:00:01Z · Confidence: medium

Hunt Hypothesis

This detection identifies adversaries establishing a web shell by creating an anomalous “404.asp” file, which often serves as a covert entry point for remote command execution and lateral movement within compromised web servers. Proactively hunting for this specific artifact in Azure Sentinel is critical to rapidly identify and neutralize persistent threats that leverage standard error pages to mask malicious activity before they escalate into broader network compromises.

YARA Rule

rule webshell_asp_404 {
	meta:
		description = "Web Shell - file 404.asp"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		date = "2014/01/28"
		score = 70
		hash = "d9fa1e8513dbf59fa5d130f389032a2d"
		id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
	strings:
		$s0 = "lFyw6pd^DKV^4CDRWmmnO1GVKDl:y& f+2"
	condition:
		all of them
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are specific false positive scenarios for the Web Shell - file 404.asp detection rule, including actionable filters and exclusions:

Original source: https://github.com/Neo23x0/signature-base/blob/main/yara/thor-webshells.yar