This rule detects adversaries establishing a persistent web shell named PHPRemoteView.php to execute remote commands and maintain access within web-facing applications. Proactive hunting for this artifact in Azure Sentinel is critical because such shells often serve as an initial foothold for lateral movement, data exfiltration, or privilege escalation that may evade standard signature-based detection.
rule webshell_PHPRemoteView {
meta:
description = "Web Shell - file PHPRemoteView.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "29420106d9a81553ef0d1ca72b9934d9"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s2 = "<input type=submit value='\".mm(\"Delete all dir/files recursive\").\" (rm -fr)'"
$s4 = "<a href='$self?c=delete&c2=$c2&confirm=delete&d=\".urlencode($d).\"&f=\".u"
condition:
1 of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Web Shell - file PHPRemoteView.php detection rule, including suggested filters and exclusions:
Scenario: Legitimate Deployment via CI/CD Pipeline
PHPRemoteView.php as part of the standard artifact bundle for the customer portal.jenkins-agent.exe, gitlab-runner) and the user context is a dedicated service account (e.g., svc-deploy).ProcessName IN ('jenkins-agent.exe', 'gitlab-runner') AND UserAccount CONTAINS 'svc-'Scenario: Scheduled Backup or Migration Job
PHPRemoteView.php to restore specific configurations without modifying the core logic.sccm-agent).Time BETWEEN '02:00' AND '04:00' AND ProcessName = 'ccmexec.exe' AND UserAccount = 'sccm-agent'Scenario: Admin Manual Configuration via Remote Desktop