This detection identifies the creation of a suspicious web shell named s-u.php, which adversaries often deploy to establish persistent access and execute commands on compromised web servers. A proactive hunt is essential in Azure Sentinel because web shells serve as a critical foothold for post-exploitation activities, allowing attackers to maintain stealthy control over the environment while evading standard traffic-based monitoring.
rule webshell_php_s_u {
meta:
description = "Web Shell - file s-u.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "efc7ba1a4023bcf40f5e912f1dd85b5a"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s6 = "<a href=\"?act=do\"><font color=\"red\">Go Execute</font></a></b><br /><textarea"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file s-u.php detection rule, including suggested filters and exclusions:
Scenario: Automated Backup Script Execution
s-u.php to orchestrate daily snapshot uploads. This script is executed by the system account (SYSTEM) via a scheduled task every night at 02:00 AM, creating the file in the web root directory as part of its initialization routine.Source User is NT AUTHORITY\SYSTEM and the File Path matches C:\inetpub\vhosts\backup-tools\s-u.php. Additionally, apply a time-based filter to ignore alerts generated between 01:30 AM and 03:00 AM on weekdays.Scenario: DevOps CI/CD Pipeline Deployment
jenkins-build) automatically provisions a temporary utility script named s-u.php within the staging web server to verify database connectivity before pushing new code. This file is created, used for 5 minutes, and then deleted or overwritten in subsequent runs.Source IP Address belonging to the Jenkins controller subnet (e.g., 10.20.40.x) and the Process Name being java.exe (Jenkins agent). The filter should also check for a file age of less than 60 minutes, assuming legitimate deployments are transient or recently created.Scenario: Third-Party Analytics Agent Installation