This detection identifies adversaries deploying a web shell named ntdaddy.asp to establish persistence and execute commands on compromised IIS servers within the Azure environment. Proactive hunting for this specific artifact is critical because web shells often serve as an initial foothold for lateral movement and data exfiltration, requiring immediate investigation before the adversary can expand their presence undetected.
rule webshell_asp_ntdaddy {
meta:
description = "Web Shell - file ntdaddy.asp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "c5e6baa5d140f73b4e16a6cfde671c68"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s9 = "if FP = \"RefreshFolder\" or "
$s10 = "request.form(\"cmdOption\")=\"DeleteFolder\" "
condition:
1 of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Web Shell - file ntdaddy.asp detection rule, along with targeted filters and exclusions:
Scenario: Scheduled Backup or Reporting Job Execution
ntdaddy.asp file in the IIS wwwroot directory to generate status logs before deleting it immediately after processing. The rule triggers because the file is created by a service account rather than an interactive user session.vbrsvc.exe, commvault.cmd) or where the User Account belongs to the “Backup-Service” group. Additionally, add a filter for files with an age of less than 5 minutes that are subsequently deleted within the same hour.Scenario: Automated Patching and Configuration Management Tool Deployment
ntdaddy.asp as a standard diagnostic component for the new application version. The file is created by the System account during a maintenance window.Ansible.exe, puppet-agent.exe). Filter out events occurring strictly between 02:00 and 04:00 AM local time.Scenario: Third-Party Web Application Installation or Upgrade