← Back to SOC feed Coverage →

Web Shell - file config.php

yara HIGH signature-base
florian-rothwebshell
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at signature-base →
Retrieved: 2026-08-08T11:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies adversaries deploying a malicious web shell named config.php to establish persistent access and execute commands on compromised Azure web servers. Proactive hunting for this specific artifact is critical because attackers often disguise web shells as legitimate configuration files to evade standard file integrity checks, enabling them to maintain long-term footholds within the environment.

YARA Rule

rule webshell_phpshell_2_1_config {
	meta:
		description = "Web Shell - file config.php"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		date = "2014/01/28"
		score = 70
		hash = "bd83144a649c5cc21ac41b505a36a8f3"
		id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
	strings:
		$s1 = "; (choose good passwords!).  Add uses as simple 'username = \"password\"' lines." fullword
	condition:
		all of them
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Here are 5 specific false positive scenarios for the Web Shell - file config.php detection rule, including suggested filters and exclusions:

Original source: https://github.com/Neo23x0/signature-base/blob/main/yara/thor-webshells.yar