This detection identifies adversaries deploying the specific “aZRaiLPhp v1.0.php” web shell to establish persistent command-and-control access on Azure-hosted web servers. Proactive hunting for this artifact is critical because web shells often serve as a stealthy entry point for lateral movement and data exfiltration that may evade standard signature-based alerts.
rule webshell_aZRaiLPhp_v1_0 {
meta:
description = "Web Shell - file aZRaiLPhp v1.0.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "26b2d3943395682e36da06ed493a3715"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s5 = "echo \" <font color='#0000FF'>CHMODU \".substr(base_convert(@fileperms($"
$s7 = "echo \"<a href='./$this_file?op=efp&fname=$path/$file&dismi=$file&yol=$path'><fo"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file aZRaiLPhp v1.0.php detection rule, including suggested filters and exclusions:
Scenario: Automated Deployment via CI/CD Pipeline
aZRaiLPhp utility during nightly build cycles. The pipeline pushes this specific file to the web root (/var/www/html/tools) as part of a standard infrastructure update, triggering the rule immediately upon creation.svc-deploy-github). Add a filter where Source User equals svc-deploy-github AND File Path contains /tools/aZRaiLPhp v1.0.php.Scenario: Scheduled Maintenance Script Execution
aZRaiLPhp module to check server health. This legitimate administrative task mimics web shell behavior by writing the file during off-hours.Process Name is svchost.exe (Windows) or cron (Linux) AND Event Time falls between 01:30 AM and 04:30 AM on Mondays.Scenario: Third-Party Monitoring Agent Installation
aZRaiLPhp v1.0.php as a custom integration module