This detection identifies adversaries deploying a malicious web shell named sql.php to establish persistent access and execute arbitrary commands on compromised web servers. Proactive hunting for this specific artifact in Azure Sentinel is critical because web shells often serve as an initial foothold that enables attackers to pivot laterally, exfiltrate sensitive data, or escalate privileges before triggering broader alerting mechanisms.
rule webshell_PHP_sql {
meta:
description = "Web Shell - file sql.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "2cf20a207695bbc2311a998d1d795c35"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "$result=mysql_list_tables($db) or die (\"$h_error<b>\".mysql_error().\"</b>$f_"
$s4 = "print \"<a href=\\\"$_SERVER[PHP_SELF]?s=$s&login=$login&passwd=$passwd&"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file sql.php detection rule, along with recommended filters and exclusions:
Scenario: Automated Database Backup Script Execution
sql.php located in the /var/www/html/admin/backup/ directory. This script connects to the SQL database to export logs and does not persist as an interactive shell but runs as a batch process.*/admin/backup/sql.php where the parent process is the scheduler service (e.g., TaskScheduler.exe on Windows or cron on Linux) and the execution duration is under 5 minutes.Scenario: CMS Plugin Update and Configuration
sql.php. This file is used by the CMS to run migration queries directly from the web interface during the update process. The file exists in the standard application directory /var/www/html/cms/modules/db-tools/.*/cms/modules/*) where the file hash matches a baseline “known good” hash stored in the asset inventory, and the user context is a service account (e.g., svc-webapp or iis_app_pool).Scenario: Third-Party Reporting Tool Integration
sql.php script in