This detection identifies the creation of a cmdasp.asp web shell file, indicating an adversary has established a persistent foothold to execute commands and maintain access on a compromised web server. Proactively hunting for this artifact in Azure Sentinel is critical because web shells often serve as the initial entry point for lateral movement and data exfiltration attacks that may evade standard signature-based defenses.
rule webshell_asp_cmdasp {
meta:
description = "Web Shell - file cmdasp.asp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "57b51418a799d2d016be546f399c2e9b"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "<%= \"\\\\\" & oScriptNet.ComputerName & \"\\\" & oScriptNet.UserName %>" fullword
$s7 = "Call oScript.Run (\"cmd.exe /c \" & szCMD & \" > \" & szTempFile, 0, True)" fullword
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file cmdasp.asp detection rule, along with recommended filters or exclusions:
Scenario: Automated Deployment via CI/CD Pipeline
cmdasp.asp (used for internal diagnostics) into the IIS root directory (C:\inetpub\wwwroot\Apps\Internal).NT SERVICE\AzureDevOpsAgent) and restrict the detection to paths outside of known deployment directories like \Apps\ or \DeployedContent\.Scenario: Scheduled Maintenance Script Execution
cmdasp.asp to generate server health reports. This script is triggered by the account DOMAIN\AdminMaintenance at 02:00 AM every day, creating or modifying the file in the \Scripts\Maintenance\ folder.DOMAIN\AdminMaintenance account within the specific directory path \Scripts\Maintenance\.Scenario: Legacy Application Migration
cmdasp.asp as its primary command interface. The file is copied by the DOMAIN\BackupService account during the initial sync phase.