This detection identifies adversaries deploying malicious web shells that exploit specific PHP version vulnerabilities to bypass safe mode restrictions and establish a persistent command-and-control foothold on compromised servers. Proactive hunting for this behavior in Azure Sentinel is critical because these web shells often operate with low visibility, allowing attackers to execute arbitrary code and exfiltrate sensitive data before traditional alerts trigger.
rule webshell_Safe_Mode_Bypass_PHP_4_4_2_and_PHP_5_1_2 {
meta:
description = "Web Shell - file Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "49ad9117c96419c35987aaa7e2230f63"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "die(\"\\nWelcome.. By This script you can jump in the (Safe Mode=ON) .. Enjoy\\n"
$s1 = "Mode Shell v1.0</font></span></a></font><font face=\"Webdings\" size=\"6\" color"
condition:
1 of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are the documented false positive scenarios for the Web Shell - file Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2.php detection rule:
Legacy CMS Plugin Updates via Deployment Pipeline
.php files in the wp-content/uploads directory that mimic the Safe_Mode bypass signature.jenkins-agent, ansible-runner, or gitlab-runner and the destination path contains /uploads/ or /plugins/.Automated Backup and Archiving Jobs
.php extensions to verify integrity before archiving, triggering the rule due to the file naming convention and PHP version context.svc_backup, vc_agent, or commvault_service when the action is “File Created” within the root web directory during defined backup windows (e.g., 02:00–04:00 UTC).Third-Party Analytics and Monitoring Agents
.php files that utilize Safe_Mode bypass techniques for environment variable inspection, causing