This detection identifies adversary behavior where a malicious web shell named asd.jsp is deployed to establish a persistent foothold and enable remote command execution on web servers. A SOC team should proactively hunt for this artifact in Azure Sentinel because web shells are frequently used as the initial entry point for post-exploitation activities, allowing attackers to maintain stealthy access while executing arbitrary commands within the environment.
rule webshell_jsp_asd {
meta:
description = "Web Shell - file asd.jsp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "a042c2ca64176410236fcc97484ec599"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s3 = "<%@ page language=\"java\" pageEncoding=\"gbk\"%>" fullword
$s6 = "<input size=\"100\" value=\"<%=application.getRealPath(\"/\") %>\" name=\"url"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the “Web Shell - file asd.jsp” detection rule, including suggested filters and exclusions:
Scenario: Automated Deployment Pipeline Artifacts
asd.jsp to the web root during nightly builds or smoke testing phases. These files are created by the build agent rather than a malicious actor and contain standard boilerplate code.jenkins-agent.exe, gitlab-runner) and the user context is a service account (e.g., svc-deployer). Additionally, filter out files created in specific directories designated for temporary builds (e.g., /tmp/staging/ or C:\Builds\Staging\).Scenario: Scheduled Maintenance Scripts by System Administrators
asd.jsp to run scheduled health checks, log rotation tasks, or database connectivity tests via the web interface. This is often done manually during maintenance windows using tools like IIS Manager or custom PowerShell scripts executed as an admin user.User field matches known administrative accounts (e.g., DOMAIN\Admin, svc-iis) and the event timestamp falls within defined maintenance windows (e.g., 02:00–04:00 UTC on Sundays).Scenario: Development Environment Testing by QA Teams
asd.jsp file to verify new server configurations, load balancers, or SSL certificates. This is