This detection identifies the creation of a suspicious web shell named b37.php, which adversaries often deploy to establish persistent access and execute commands on compromised web servers. Proactively hunting for this artifact in Azure Sentinel is critical because web shells serve as a primary foothold for attackers to pivot laterally, exfiltrate sensitive data, or maintain long-term control over the environment.
rule webshell_PHP_b37 {
meta:
description = "Web Shell - file b37.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "0421445303cfd0ec6bc20b3846e30ff0"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "xmg2/G4MZ7KpNveRaLgOJvBcqa2A8/sKWp9W93NLXpTTUgRc"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Web Shell - file b37.php detection rule, including suggested filters and exclusions:
Scheduled Backup Script Execution
b37.php. This script is located in the /var/www/html/backups/ directory and executes automatically every day at 02:00 AM to archive database logs. Because the file name matches the rule exactly, the automated execution triggers an alert even though it is a known, benign process.ends with /backups/b37.php) and restrict alerts to non-business hours (e.g., 01:00–04:00) or exclude if the user context is a dedicated service account like svc-backup or cron.CMS Plugin Update via Admin Panel
b37.php within the /admin/modules/updates/ directory. This legitimate administrative activity mimics the behavior of a web shell upload.10.10.x.x) and the HTTP User-Agent string contains specific identifiers for the CMS admin interface, such as CMS-Admin-Browser or the company’s standard browser signature.CI/CD Pipeline Deployment Artifact