This detection identifies adversary behavior where a malicious web shell named “G5.php” is deployed to establish persistent access and execute commands on compromised web servers. The SOC team should proactively hunt for this artifact in Azure Sentinel because web shells serve as critical footholds that enable attackers to pivot laterally, exfiltrate sensitive data, or maintain long-term undetected presence within the environment.
rule webshell_PHP_G5 {
meta:
description = "Web Shell - file G5.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "95b4a56140a650c74ed2ec36f08d757f"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s3 = "echo \"Hacking Mode?<br><select name='htype'><option >--------SELECT--------</op"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 3-5 specific false positive scenarios for the Web Shell - file G5.php detection rule, including targeted filters and exclusions:
Automated Backup or Migration Scripts: Enterprise backup solutions (e.g., Veeam, Commvault) or migration tools often generate temporary PHP scripts named G5.php within web root directories to handle data synchronization tasks. These files are created by the service account rather than a malicious actor and contain standard logic for file I/O operations that mimic shell behavior.
DOMAIN\VeeamService) AND the file path resides within known backup staging directories (e.g., /var/www/html/migration_staging/).Scheduled CMS Maintenance Jobs: Content Management Systems like WordPress, Drupal, or custom enterprise portals often utilize scheduled cron jobs that deploy a maintenance script named G5.php to perform database integrity checks or cache clearing. This file is typically executed via the system scheduler (e.g., Linux cron or Windows Task Scheduler) rather than through an HTTP request from an external IP.
crond, TaskScheduler) AND the execution time aligns with defined maintenance windows (e.g., 02:00–04:00 UTC).CI/CD Pipeline Deployment Artifacts: During automated deployment cycles using tools like Jenkins, GitLab CI, or Azure DevOps, the pipeline may temporarily instantiate G5.php as a health-check endpoint or a deployment verification script before finalizing the release. This is a legitimate part of the “blue-green” deployment strategy where the file exists briefly in the staging environment.