This detection identifies adversaries establishing a web shell named “404.php” to maintain persistent access and execute commands on compromised web servers. Proactive hunting for this specific artifact in Azure Sentinel is critical because attackers often disguise malicious shells as standard error pages to evade routine monitoring while enabling lateral movement and data exfiltration.
rule webshell_caidao_shell_404 {
meta:
description = "Web Shell - file 404.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "ee94952dc53d9a29bdf4ece54c7a7aa7"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "<?php $K=sTr_RepLaCe('`','','a`s`s`e`r`t');$M=$_POST[ice];IF($M==NuLl)HeaDeR('St"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 4 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file 404.php detection rule, including suggested filters and exclusions:
Scenario: Automated Health Check by Load Balancer
404.php as a lightweight heartbeat endpoint, the system may interpret this legitimate file access as a suspicious web shell creation or execution attempt.Scenario: Scheduled Backup and Integrity Verification
404.php to confirm the web server’s file system integrity before archiving, triggering a “file creation/access” alert that mimics a shell upload.ansible-runner or veeam-agent.Scenario: CI/CD Pipeline Deployment Artifacts
404.php is frequently part of