This rule detects adversaries deploying a malicious web shell named elmaliseker.asp to establish persistence and execute commands on compromised web servers within the Azure environment. Proactive hunting for this specific file is critical because web shells often serve as an initial foothold for attackers, enabling them to move laterally across the network or exfiltrate sensitive data before traditional alerts trigger.
rule webshell_elmaliseker_2 {
meta:
description = "Web Shell - file elmaliseker.asp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "b32d1730d23a660fd6aa8e60c3dc549f"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s1 = "<td<%if (FSO.GetExtensionName(path & \"\\\" & oFile.Name)=\"lnk\") or (FSO.GetEx"
$s6 = "<input type=button value=Save onclick=\"EditorCommand('Save')\"> <input type=but"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Web Shell - file elmaliseker.asp detection rule, including targeted filters and exclusions:
Scheduled Backup Job Execution
elmaliseker.asp within the C:\inetpub\wwwroot\App_Reports directory to verify checksum integrity before archiving.DOMAIN\VeeamBackupSvc) in the backup staging folder path: C:\inetpub\wwwroot\App_Reports\*.asp.Legacy CRM Module Deployment
elmaliseker.asp used for email validation logic, which is deployed to the production server via an automated CI/CD pipeline during business hours.DOMAIN\DevOpsBot) and the file path contains \Modules\CRM\Utils\.Automated Security Scanning Tool
elmaliseker.asp into the public directory to verify HTTP response headers and file permissions before removing it immediately after the scan completes.