This detection identifies adversaries deploying a malicious web shell named metaslsoft.php to establish persistent access and execute commands on compromised web servers. Proactive hunting for this specific artifact in Azure Sentinel is critical because web shells often serve as an initial foothold that enables attackers to escalate privileges, exfiltrate data, or move laterally across the environment before triggering broader alerts.
rule webshell_metaslsoft {
meta:
description = "Web Shell - file metaslsoft.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "aa328ed1476f4a10c0bcc2dde4461789"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s7 = "$buff .= \"<tr><td><a href=\\\"?d=\".$pwd.\"\\\">[ $folder ]</a></td><td>LINK</t"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file metaslsoft.php detection rule, including suggested filters or exclusions:
Scenario: Legitimate Deployment via CI/CD Pipeline
metaslsoft.php as part of a standard module update for the internal reporting dashboard.10.20.50.x) and the process name is svc-jenkins or github-runner. Additionally, filter based on a time window (e.g., 02:00–04:00 UTC) when deployments are known to occur.Scenario: Scheduled Backup and Maintenance Job
metaslsoft.php to log backup status metrics before archiving the file.powershell.exe, cscagent.exe, or taskeng.exe. Furthermore, filter by file modification time if the change occurs exactly at a scheduled minute (e.g., 03:15 AM daily) and the user context is a dedicated service account like svc-webmaint.Scenario: Admin Manual Configuration via Remote Desktop
metaslsoft.php during a change request window