Potential Webshell Creation On Static Website

 Original Source: [Sigma source]
Title: Potential Webshell Creation On Static Website
Status: test
Description:Detects the creation of files with certain extensions on a static web site. This can be indicative of potential uploads of a web shell.
References:
  -PT ESC rule and personal experience
  -https://github.com/swisskyrepo/PayloadsAllTheThings/blob/c95a0a1a2855dc0cd7f7327614545fe30482a636/Upload%20Insecure%20Files/README.md
Author: Beyu Denis, oscd.community, Tim Shelton, Thurein Oo
Date: 2019-10-22
modified:2023-10-15
Tags:
  • -'attack.persistence'
  • -'attack.t1505.003'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection_wwwroot_path:
    TargetFilename|contains: '\inetpub\wwwroot\'
  selection_wwwroot_ext:
    TargetFilename|contains:
      -'.ashx'
      -'.asp'
      -'.ph'
      -'.soap'

  selection_htdocs_path:
    TargetFilename|contains:
      -'\www\'
      -'\htdocs\'
      -'\html\'

  selection_htdocs_ext:
    TargetFilename|contains: '.ph'
  filter_main_temp:
    TargetFilename|contains:
      -'\AppData\Local\Temp\'
      -'\Windows\Temp\'

  filter_main_system:
    Image: 'System'
  filter_main_legitimate:
    TargetFilename|contains: '\xampp'
  condition:(all of selection_wwwroot_* or all of selection_htdocs_*) and not 1 of filter_main_*
Falsepositives:
  -Legitimate administrator or developer creating legitimate executable files in a web application folder
Level: medium