This detection targets adversaries who deploy malicious web shells named idc.php to establish a persistent foothold and execute arbitrary commands on compromised web servers. Proactive hunting for this specific artifact in Azure Sentinel is critical because web shells often serve as an initial entry point for lateral movement and data exfiltration, requiring immediate investigation before the attacker can expand their presence within the environment.
rule webshell_wsb_idc {
meta:
description = "Web Shell - file idc.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "7c5b1b30196c51f1accbffb80296395f"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s1 = "if (md5($_GET['usr'])==$user && md5($_GET['pass'])==$pass)" fullword
$s3 = "{eval($_GET['idc']);}" fullword
condition:
1 of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file idc.php detection rule, including suggested filters and exclusions:
Scenario: Automated Backup Script Execution
idc.php file in the /var/www/html/backup/ directory to store session data before archiving.Path contains "/backup/" OR Path contains "/temp/". Additionally, exclude if the file size is under 2KB and modified by the service account svc-backup-agent.Scenario: CMS Plugin Update Deployment
idc.php into the active plugins directory (/wp-content/plugins/idc-analytics/) as part of the installation routine./wp-content/plugins/*, /modules/custom/*). Filter by source IP, allowing only deployments originating from the CI/CD pipeline server (e.g., Source IP = 10.20.30.5 for Jenkins or GitLab Runner).Scenario: Scheduled Health Check Job