This detection identifies the creation of a suspicious web shell named ice.asp, which adversaries often deploy to establish persistent access and execute commands on compromised web servers. A proactive hunt is essential in Azure Sentinel because web shells serve as a critical foothold for lateral movement and data exfiltration, allowing attackers to maintain stealthy control over the environment even after initial breach detection.
rule webshell_asp_ice {
meta:
description = "Web Shell - file ice.asp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "d141e011a92f48da72728c35f1934a2b"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "D,'PrjknD,J~[,EdnMP[,-4;DS6@#@&VKobx2ldd,'~JhC"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file ice.asp detection rule, along with suggested filters or exclusions:
Scenario: Automated Backup and Monitoring Scripts
ice.asp to report real-time job health. These files are created by the service account during scheduled maintenance windows rather than user interaction.Source User is a known service account (e.g., SYSTEM, VeeamServiceAccount) and the Process Name matches the backup agent executable (e.g., vcagent.exe).Scenario: Legacy Intranet Portal Deployment
ice.asp as a static landing page or status indicator for the HR or IT helpdesk section.Path. If the file is created within a known deployment directory (e.g., \Intranet\HR\Status\) and the Process Name belongs to the deployment tool (e.g., msbuild.exe, octopus.exe, or powershell.exe running a specific script), suppress the alert.Scenario: Scheduled Health Check Jobs
ice.asp containing JSON or XML logs, which is immediately deleted after processing.