This detection identifies adversaries deploying an mdb.asp web shell to establish a persistent foothold and execute commands on compromised IIS servers. Proactive hunting for this specific artifact in Azure Sentinel is critical because web shells often serve as the initial entry point for lateral movement and data exfiltration, requiring immediate investigation before attackers can expand their presence.
rule webshell_caidao_shell_mdb {
meta:
description = "Web Shell - file mdb.asp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "fbf3847acef4844f3a0d04230f6b9ff9"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s1 = "<% execute request(\"ice\")%>a " fullword
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file mdb.asp detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Automated Reporting Generation by Business Intelligence Tools
.asp files named mdb.asp (or similar) in the IIS web root to render dynamic database connection reports. These files are created, executed, and sometimes deleted by the application service account during scheduled report refreshes.w3wp.exe running under the IIS AppPool\ReportServerAppPool (or specific BI app pools) and the user principal name matches the BI Service Account (e.g., svc-bi-reporting).Scenario: Legacy Database Migration Scripts
mdb.asp to process the file conversion before cleanup. This is common in environments utilizing Microsoft Access Services or custom .NET wrappers for data ingestion.C:\InetPub\wwwroot\Maintenance\mdb.asp. Additionally, filter out events where the file size remains constant or is deleted within 15 minutes of creation.Scenario: Scheduled Health Check Probes by Load Balancers