This detection identifies adversaries establishing a persistent web shell named “v1.0.php” to execute commands and maintain access via a MySQL interface on compromised web servers. Proactive hunting for this specific artifact in Azure Sentinel is critical because web shells often serve as the initial foothold for lateral movement and data exfiltration, requiring immediate investigation before attackers can deepen their presence within the environment.
rule webshell_Mysql_interface_v1_0 {
meta:
description = "Web Shell - file Mysql interface v1.0.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "a12fc0a3d31e2f89727b9678148cd487"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "echo \"<td><a href='$PHP_SELF?action=dropDB&dbname=$dbname' onClick=\\\"return"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file Mysql interface v1.0.php detection rule, along with recommended filters and exclusions:
Scenario: Automated Database Backup Script Execution
mysqldump that invokes a custom PHP wrapper (v1.0.php) to log backup status into the web server’s directory before archiving. This legitimate script is often located in /var/www/html/admin/backup/.*/admin/backup/v1.0.php AND the source IP belongs to the internal backup server subnet (e.g., 192.168.10.x).Scenario: CMS Plugin Update via Admin Dashboard
v1.0.php in the uploads directory before finalizing the installation.POST or PUT, indicating an active management session rather than a suspicious anonymous upload.Scenario: CI/CD Pipeline Deployment Artifact
v1.0.php, to the staging web server via an SSH/S