← Back to SOC feed Coverage →

Web Shell - file Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2.php

yara HIGH signature-base
evasionflorian-rothwebshell
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at signature-base →
Retrieved: 2026-08-07T23:00:00Z · Confidence: medium

Hunt Hypothesis

This detection identifies adversaries deploying malicious web shells that exploit specific PHP version vulnerabilities to bypass safe mode restrictions and establish a persistent command-and-control foothold on compromised servers. Proactive hunting for this behavior in Azure Sentinel is critical because these web shells often operate with low visibility, allowing attackers to execute arbitrary code and exfiltrate sensitive data before traditional alerts trigger.

YARA Rule

rule webshell_Safe_Mode_Bypass_PHP_4_4_2_and_PHP_5_1_2 {
	meta:
		description = "Web Shell - file Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2.php"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		date = "2014/01/28"
		score = 70
		hash = "49ad9117c96419c35987aaa7e2230f63"
		id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
	strings:
		$s0 = "die(\"\\nWelcome.. By This script you can jump in the (Safe Mode=ON) .. Enjoy\\n"
		$s1 = "Mode Shell v1.0</font></span></a></font><font face=\"Webdings\" size=\"6\" color"
	condition:
		1 of them
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 2 string patterns in its detection logic.

False Positive Guidance

Here are the documented false positive scenarios for the Web Shell - file Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2.php detection rule:

Original source: https://github.com/Neo23x0/signature-base/blob/main/yara/thor-webshells.yar