This detection identifies the creation of a malicious mysqlwebsh.php web shell, indicating an adversary has established a persistent foothold to execute arbitrary commands on a compromised web server. Proactively hunting for this specific artifact in Azure Sentinel is critical because web shells often serve as the initial entry point for lateral movement and data exfiltration, allowing defenders to isolate threats before they escalate into broader infrastructure compromises.
rule webshell_mysqlwebsh {
meta:
description = "Web Shell - file mysqlwebsh.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "babfa76d11943a22484b3837f105fada"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s3 = " <TR><TD bgcolor=\"<? echo (!$CONNECT && $action == \"chparam\")?\"#660000\":\"#"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Web Shell - file mysqlwebsh.php detection rule, along with suggested filters and exclusions:
Automated Database Backup Scripts
mysqlwebsh.php in the web root directory (/var/www/html/backups) to facilitate the export of MySQL data before deletion./backups/mysqlwebsh.php AND the process creating the file is identified as a known service account (e.g., svc_backup_agent or cron).CMS Plugin Deployment via CI/CD Pipeline
mysqlwebsh.php within the /wp-content/plugins/db-monitor/ directory. This is a standard artifact of the release process, not an intrusion.10.20.50.x) AND the file modification timestamp aligns with a scheduled deployment window (e.g., 02:00–04:00 UTC).Third-Party Analytics Integration
mysqlwebsh.php into the `/