This detection identifies the creation of a suspicious web shell named g00nv13.php, which adversaries often deploy to establish persistent command-and-control access and execute arbitrary commands on compromised web servers. Proactively hunting for this artifact in Azure Sentinel is critical because web shells serve as a primary foothold for attackers, enabling them to pivot laterally within the environment or exfiltrate sensitive data before traditional alerts trigger.
rule webshell_PHP_g00nv13 {
meta:
description = "Web Shell - file g00nv13.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "35ad2533192fe8a1a76c3276140db820"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s1 = "case \"zip\": case \"tar\": case \"rar\": case \"gz\": case \"cab\": cas"
$s4 = "if(!($sqlcon = @mysql_connect($_SESSION['sql_host'] . ':' . $_SESSION['sql_p"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Web Shell - file g00nv13.php detection rule, including suggested filters and exclusions:
Scenario: Automated Backup Script Execution by Admin Tools
g00nv13.php might be a generated artifact during a nightly backup window where the tool creates a lightweight interface for log retrieval.DOMAIN\BackupService) and Process Name (e.g., vbr.exe or acronisagent.exe). Additionally, exclude files created during specific maintenance windows (e.g., 02:00–04:00 UTC) where the filename matches g00nv13.php.Scenario: Scheduled CMS Maintenance Job
g00nv13.php to verify database connectivity or cache status before the main application restarts. This is common in environments using Plesk or cPanel.cron, Task Scheduler.exe) and the file path resides within a designated maintenance directory (e.g., /var/www/html/maintenance/). Implement a rule to suppress alerts if the file’s creation time aligns with the configured cron schedule.**Scenario: