This detection identifies potential web shell deployments where adversaries create or modify an ‘a.php’ file to establish a persistent foothold for remote command execution and lateral movement within the environment. Proactive hunting is essential in Azure Sentinel because attackers often utilize generic filenames like ‘a.php’ to evade signature-based detections, requiring behavioral analysis to uncover hidden malicious activity before it escalates into a broader compromise.
rule webshell_PHP_a {
meta:
description = "Web Shell - file a.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "e3b461f7464d81f5022419d87315a90d"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s1 = "echo \"<option value=\\\"\". strrev(substr(strstr(strrev($work_dir), \"/\""
$s2 = "echo \"<option value=\\\"$work_dir\\\" selected>Current Directory</option>"
$s4 = "<input name=\"submit_btn\" type=\"submit\" value=\"Execute Command\"></p> " fullword
condition:
2 of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the “Web Shell - file a.php” detection rule, including suggested filters and exclusions:
Scenario: Automated Backup or Migration Tool Deployment
a.php to specific directories (e.g., /var/www/html/maintenance/) to verify connectivity or initiate data transfer before the main job runs. These files are created by service accounts, not interactive users.Veeam.Backup.Service.exe or powershell.exe) and the source user account belongs to the Backup-Admins group.Scenario: Scheduled CMS Maintenance Tasks
a.php during routine maintenance windows (e.g., database optimization or cache clearing). This often occurs at 2:00 AM UTC when no human interaction is expected.*/wp-content/maintenance/ or */public_html/scripts/).Scenario: DevOps CI/CD Pipeline Artifact Upload
a.php to the staging environment to validate server health before promoting the full application build. This is triggered by the SYSTEM or `