This hunt detects adversaries establishing a persistent web shell named iMHaPFtp.php to execute arbitrary commands and maintain access within Azure-hosted web applications. Proactively hunting for this artifact in Azure Sentinel is critical because web shells often serve as an initial foothold for attackers, enabling them to pivot laterally across the environment before triggering standard alerting mechanisms.
rule webshell_iMHaPFtp_2 {
meta:
description = "Web Shell - file iMHaPFtp.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "12911b73bc6a5d313b494102abcf5c57"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s8 = "if ($l) echo '<a href=\"' . $self . '?action=permission&file=' . urlencode($"
$s9 = "return base64_decode('R0lGODlhEQANAJEDAMwAAP///5mZmf///yH5BAHoAwMALAAAAAARAA0AAA"
condition:
1 of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file iMHaPFtp.php detection rule, along with recommended filters or exclusions:
Scenario: Automated Backup Script Execution
iMHaPFtp.php within the web root to offload logs via FTP before being archived. This file is created daily at 02:00 AM by the service account svc-backup.Source User equals svc-backup AND File Path contains \webroot\temp\backup\iMHaPFtp.php during the time window 01:30–02:30.Scenario: CI/CD Pipeline Deployment Artifact
iMHaPFtp.php as part of the standard artifact bundle before the application container restarts. This occurs on the host build-server-04.Host Name matches build-server-04 AND Process Name is java.exe (Jenkins agent) or powershell.exe, provided the file creation timestamp aligns with the scheduled deployment window.Scenario: Third-Party Plugin Installation
iMHaPFtp.php in the /plugins/ftp-manager/ directory to handle initial configuration and credential exchange.