This detection identifies adversaries deploying a malicious “redirect.asp” web shell to establish persistence and execute commands on compromised web servers. Proactive hunting for this artifact in Azure Sentinel is critical because web shells often serve as an initial foothold for lateral movement and data exfiltration, requiring immediate investigation before attackers can escalate privileges or move deeper into the environment.
rule webshell_redirect {
meta:
description = "Web Shell - file redirect.asp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "97da83c6e3efbba98df270cc70beb8f8"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s7 = "var flag = \"?txt=\" + (document.getElementById(\"dl\").checked ? \"2\":\"1\" "
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file redirect.asp detection rule, along with suggested filters or exclusions:
Scenario: Automated Backup and Archiving Tools
redirect.asp files in standard IIS directories (C:\inetpub\wwwroot) to handle session handoffs between the agent and the central server.Veeam.Backup.Service.exe, commvault.cmd) or where the file path resides within dedicated backup directories rather than dynamic web root folders.Scenario: Scheduled Maintenance and Health Checks
redirect.asp file to log the status of the application pool or redirect users to a “Maintenance Mode” page during deployment windows (e.g., running via cscript.exe or powershell.exe).SYSTEM, NT AUTHORITY\NETWORK SERVICE) and the file size remains under a specific threshold (e.g., <5KB), indicating a lightweight status script rather than a complex web shell.Scenario: Legacy Application Deployment via CI/CD Pipelines