This detection identifies adversaries establishing a persistent web shell via the specific zehir.asp file to execute commands and maintain access within the Azure environment. Proactively hunting for this artifact is critical because web shells often serve as an initial foothold for attackers to pivot laterally, exfiltrate sensitive data, or escalate privileges before broader security controls are triggered.
rule webshell_ASP_zehir {
meta:
description = "Web Shell - file zehir.asp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "0061d800aee63ccaf41d2d62ec15985d"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s9 = "Response.Write \"<font face=wingdings size=3><a href='\"&dosyaPath&\"?status=18&"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file zehir.asp detection rule, along with recommended filters and exclusions:
Scenario: Automated Backup or Migration Scripts
zehir.asp as part of a legacy template restoration process before deleting it immediately after the job completes.svc_backup, migrator_svc) and the file duration is less than 5 minutes. Alternatively, add an exclusion for the specific directory path used by these tools (e.g., \InetPub\wwwroot\temp_migration\).Scenario: Scheduled Health Check or Monitoring Agents
zehir.asp every morning at 02:00 AM to test IIS response times, which is a standard operational procedure rather than an intrusion.TaskHost.exe, SolarWinds.Agent.exe) and a time window filter allowing this specific file creation only between 01:00 and 04:00 UTC daily.Scenario: CMS Content Deployment via CI/CD Pipelines