This detection identifies adversaries deploying a malicious web shell named “Exploit.php” that leverages safe mode command execution bypass techniques to establish persistent access and execute arbitrary commands on compromised web servers. Proactive hunting for this behavior in Azure Sentinel is critical because web shells serve as a primary foothold for attackers, enabling them to pivot laterally across the environment and exfiltrate sensitive data before traditional perimeter defenses can react.
rule webshell_Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit {
meta:
description = "Web Shell - file Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "c6eeacbe779518ea78b8f7ed5f63fc11"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s1 = "<option value=\"cat /etc/passwd\">/etc/passwd</option>" fullword
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file Liz0ziM Private Safe Mode Command Execution Bypass Exploit.php detection rule, including suggested filters and exclusions:
Scenario: Automated Backup Script Execution via Cron
Liz0ziM_Private_Safe_Mode_Bypass.php (or similar variant) to perform nightly database backups. The script executes system commands using exec() or shell_exec() within the web root, mimicking the behavior of a malicious web shell.php-fpm, cron, Task Scheduler) and the file path is located in a dedicated maintenance directory (e.g., /var/www/html/maintenance/ or C:\InetPub\wwwroot\maintenance\).IF process_name IN ('php-fpm', 'crond') AND file_path CONTAINS '/maintenance/' THEN EXCLUDE.Scenario: Legitimate CI/CD Pipeline Deployment
Liz0ziM_Private_Safe_Mode_Bypass.php to initialize services or clear caches before finalizing the build.jenkins-bot, gitlab-runner) and exclude events occurring during defined maintenance windows or when the source IP belongs to the internal CI/CD subnet.