This detection identifies adversaries deploying a malicious web shell named sys3.jsp to establish persistent access and execute commands on compromised web servers. A proactive hunt is essential in Azure Sentinel to uncover hidden post-exploitation activities that evade standard signature-based alerts, ensuring early identification of potential lateral movement or data exfiltration attempts.
rule webshell_jsp_sys3 {
meta:
description = "Web Shell - file sys3.jsp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "b3028a854d07674f4d8a9cf2fb6137ec"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s1 = "<input type=\"submit\" name=\"btnSubmit\" value=\"Upload\">" fullword
$s4 = "String path=new String(request.getParameter(\"path\").getBytes(\"ISO-8859-1\""
$s9 = "<%@page contentType=\"text/html;charset=gb2312\"%>" fullword
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file sys3.jsp detection rule, along with recommended filters or exclusions:
Scenario: Automated Deployment via CI/CD Pipeline
sys3.jsp file (a standard utility component) into the web root directory (/webapps/app/sys3.jsp) during the nightly build process.10.20.50.x) and the file creation/modification timestamp aligns with the scheduled deployment window (e.g., 02:00–04:00 UTC).Scenario: Scheduled Backup Utility Execution
sys3.jsp to the web server’s staging directory before archiving. This mimics the behavior of a web shell being dropped by an attacker.vcagent.exe, vbrsvc.exe) and the file path contains specific keywords like /staging or /temp.Scenario: Application Health Check by Load Balancer
sys3.jsp log