← Back to SOC feed Coverage →

Web Shell - file Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit.php

yara HIGH signature-base
evasionexploitflorian-rothwebshell
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at signature-base →
Retrieved: 2026-08-09T23:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies adversaries deploying a malicious web shell named “Exploit.php” that leverages safe mode command execution bypass techniques to establish persistent access and execute arbitrary commands on compromised web servers. Proactive hunting for this behavior in Azure Sentinel is critical because web shells serve as a primary foothold for attackers, enabling them to pivot laterally across the environment and exfiltrate sensitive data before traditional perimeter defenses can react.

YARA Rule

rule webshell_Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit {
	meta:
		description = "Web Shell - file Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit.php"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		date = "2014/01/28"
		score = 70
		hash = "c6eeacbe779518ea78b8f7ed5f63fc11"
		id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
	strings:
		$s1 = "<option value=\"cat /etc/passwd\">/etc/passwd</option>" fullword
	condition:
		all of them
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 5 specific false positive scenarios for the Web Shell - file Liz0ziM Private Safe Mode Command Execution Bypass Exploit.php detection rule, including suggested filters and exclusions:

Original source: https://github.com/Neo23x0/signature-base/blob/main/yara/thor-webshells.yar