This detection identifies adversaries deploying a “Server Variables.asp” web shell to establish persistent command-and-control access and execute arbitrary commands on compromised web servers. Proactively hunting for this specific artifact in Azure Sentinel is critical because web shells often serve as an initial foothold for lateral movement, allowing attackers to evade standard perimeter defenses by operating within the trusted application layer.
rule webshell_Server_Variables {
meta:
description = "Web Shell - file Server Variables.asp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "47fb8a647e441488b30f92b4d39003d7"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s7 = "<% For Each Vars In Request.ServerVariables %>" fullword
$s9 = "Variable Name</B></font></p>" fullword
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file Server Variables.asp detection rule, including suggested filters and exclusions:
Scenario: Scheduled IIS Health Monitoring Script
Check-IISHealth.ps1) running via Windows Task Scheduler every 5 minutes to verify web server responsiveness. This script dynamically generates or updates an ASP file named Server Variables.asp in the root of the default IIS site (C:\inetpub\wwwroot) to log current server variables for auditing purposes.powershell.exe or svchost.exe (specifically the IIS Admin Service) and the Source User matching the service account (e.g., DOMAIN\IIS-AppPool). Additionally, exclude file creation events where the file path ends in \wwwroot\Server Variables.asp.Scenario: Automated Backup and Archiving Routine
Server Variables.asp file to capture current environment configurations before archiving the IIS directory structure.vbr.exe, commagent.exe) and the action occurs during the defined maintenance window (e.g., 02:00 – 04:00 UTC). A time-based filter can be applied to ignore alerts for this specific file outside of business hours if the backup runs exclusively at night.Scenario: Deployment Pipeline Artifact Generation