This detection identifies adversaries who have deployed a malicious web shell named zacosmall.php to establish persistent access and execute commands on compromised web servers. A proactive hunt is essential in Azure Sentinel to rapidly verify the legitimacy of this file across all web applications, preventing potential lateral movement or data exfiltration before the attacker can fully operationalize their foothold.
rule webshell_zacosmall {
meta:
description = "Web Shell - file zacosmall.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "5295ee8dc2f5fd416be442548d68f7a6"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "if($cmd!==''){ echo('<strong>'.htmlspecialchars($cmd).\"</strong><hr>"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file zacosmall.php detection rule, including suggested filters and exclusions:
Scenario: Automated Backup Script Execution
zacosmall.php in the /var/www/html/backup/ directory to orchestrate the connection between the backup agent and the web server..../backup/ or .../temp/ directories from the rule scope, provided the file modification timestamp aligns with the scheduled job window (e.g., 02:00–04:00 UTC).Scenario: CMS Theme Update Deployment
zacosmall.php as a core component of the “Zaco” plugin suite used for mobile responsiveness.Ansible-Pull or Jenkins-Agent).Scenario: Scheduled Health Check Monitoring
/health/zacosmall.php to verify API latency and service availability, triggering file access logs that mimic shell activity.