Webshell Detection With Command Line Keywords

 Original Source: [Sigma source]
Title: Webshell Detection With Command Line Keywords
Status: test
Description:Detects certain command line parameters often used during reconnaissance activity via web shells
References:
  -https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-ii.html
  -https://unit42.paloaltonetworks.com/bumblebee-webshell-xhunt-campaign/
  -https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild
Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Anton Kutepov, oscd.community, Chad Hudson, Matt Anderson
Date: 2017-01-01
modified:2026-07-14
Tags:
  • -'attack.persistence'
  • -'attack.discovery'
  • -'attack.t1505.003'
  • -'attack.t1018'
  • -'attack.t1033'
  • -'attack.t1087'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_webserver_image:
    ParentImage|endswith:
      -'\w3wp.exe'
      -'\php-cgi.exe'
      -'\nginx.exe'
      -'\httpd.exe'
      -'\caddy.exe'
      -'\ws_tomcatservice.exe'

  selection_webserver_characteristics_tomcat1:
    ParentImage|endswith:
      -'\java.exe'
      -'\javaw.exe'

    ParentImage|contains:
      -'-tomcat-'
      -'\tomcat'

  selection_webserver_characteristics_tomcat2:
    ParentImage|endswith:
      -'\java.exe'
      -'\javaw.exe'

    CommandLine|contains:
      -'catalina.jar'
      -'CATALINA_HOME'

  selection_susp_net_utility:
    OriginalFileName:
      -'net.exe'
      -'net1.exe'

    CommandLine|contains:
      -' user '
      -' use '
      -' group '

  selection_susp_ping_utility:
    OriginalFileName: 'ping.exe'
    CommandLine|contains: ' -n '
  selection_susp_change_dir:
    CommandLine|contains:
      -'&cd&echo'
      -'cd /d '

  selection_susp_wmic_utility:
    OriginalFileName: 'wmic.exe'
    CommandLine|contains: ' /node:'
  selection_susp_powershell_cli:
    Image|endswith:
      -'\cmd.exe'
      -'\powershell.exe'
      -'\pwsh.exe'

    CommandLine|contains:
      -' -enc '
      -' -EncodedCommand '
      -' -w hidden '
      -' -windowstyle hidden'
      -'.WebClient).Download'

  selection_susp_misc_discovery_binaries:
    - Image|endswith:
      - '\dsquery.exe'
      - '\find.exe'
      - '\findstr.exe'
      - '\ipconfig.exe'
      - '\netstat.exe'
      - '\nslookup.exe'
      - '\pathping.exe'
      - '\quser.exe'
      - '\schtasks.exe'
      - '\systeminfo.exe'
      - '\tasklist.exe'
      - '\tracert.exe'
      - '\wevtutil.exe'
      - '\whoami.exe'
    - OriginalFileName:
      - 'dsquery.exe'
      - 'find.exe'
      - 'findstr.exe'
      - 'ipconfig.exe'
      - 'netstat.exe'
      - 'nslookup.exe'
      - 'pathping.exe'
      - 'quser.exe'
      - 'schtasks.exe'
      - 'sysinfo.exe'
      - 'tasklist.exe'
      - 'tracert.exe'
      - 'VSSADMIN.EXE'
      - 'wevtutil.exe'
      - 'whoami.exe'
  selection_susp_misc_discovery_commands:
    CommandLine|contains:
      -' Test-NetConnection '
      -'dir \'

  condition:1 of selection_webserver_* and 1 of selection_susp_*
Falsepositives:
  -Unknown
Level: high