Antivirus Web Shell Signature Alerts (ASP/JSP/PHP/Perl/VBS and related backdoor indicators)

Alerts on AV signatures indicating web shells/backdoors (ASP/JSP/PHP/Perl/VBS/Webshell) to support fast investigation of persistence.

FreeUnreviewedSigmahighv1
title: Antivirus Web Shell Signature Alerts (ASP/JSP/PHP/Perl/VBS and related backdoor indicators)
id: 5a4d83a1-ca1d-4527-9adf-f432844c8b46
status: test
description: This rule flags antivirus detections whose signature strings indicate a web shell or web-based backdoor across multiple server-side script types (ASP, ASPX, JSP, PHP, Perl, VBS) and related “webshell” naming. Attackers often rely on web shells for persistence and remote command execution through HTTP, making these detections high priority even if the malware was blocked. The rule relies on antivirus alert telemetry that includes a signature field matched by specific prefix and substring indicators.
references:
  - https://www.nextron-systems.com/?s=antivirus
  - https://github.com/tennc/webshell
  - https://www.virustotal.com/gui/file/bd1d52289203866645e556e2766a21d2275877fbafa056a76fe0cf884b7f8819/detection
  - https://www.virustotal.com/gui/file/308487ed28a3d9abc1fec7ebc812d4b5c07ab025037535421f64c60d3887a3e8/detection
  - https://www.virustotal.com/gui/file/7d3cb8a8ff28f82b07f382789247329ad2d7782a72dde9867941f13266310c80/detection
  - https://www.virustotal.com/gui/file/e841675a4b82250c75273ebf0861245f80c6a1c3d5803c2d995d9d3b18d5c4b5/detection
  - https://www.virustotal.com/gui/file/a80042c61a0372eaa0c2c1e831adf0d13ef09feaf71d1d20b216156269045801/detection
  - https://www.virustotal.com/gui/file/b219f7d3c26f8bad7e175934cd5eda4ddb5e3983503e94ff07d39c0666821b7e/detection
  - https://www.virustotal.com/gui/file/b8702acf32fd651af9f809ed42d15135f842788cd98d81a8e1b154ee2a2b76a2/detection
  - https://www.virustotal.com/gui/file/13ae8bfbc02254b389ab052aba5e1ba169b16a399d9bc4cb7414c4a73cd7dc78/detection
  - https://github.com/SigmaHQ/sigma/blob/master/rules/category/antivirus/av_webshell.yml
author: Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team
date: 2018-09-09
modified: 2026-06-29
tags:
  - attack.persistence
  - attack.t1505.003
logsource:
  category: antivirus
detection:
  selection:
    - Signature|startswith:
        - ASP.
        - IIS/BackDoor
        - JAVA/Backdoor
        - JSP.
        - Perl.
        - PHP.
        - Troj/ASP
        - Troj/JSP
        - Troj/PHP
        - VBS/Uxor
    - Signature|contains:
        - ASP_
        - "ASP:"
        - ASP.Agent
        - ASP/
        - Aspdoor
        - ASPXSpy
        - Backdoor.ASP
        - Backdoor.Java
        - Backdoor.JSP
        - Backdoor.PHP
        - Backdoor.VBS
        - Backdoor/ASP
        - Backdoor/Java
        - Backdoor/JSP
        - Backdoor/PHP
        - Backdoor/VBS
        - C99shell
        - Chopper
        - filebrowser
        - JSP_
        - "JSP:"
        - JSP.Agent
        - JSP/
        - "Perl:"
        - Perl/
        - PHP_
        - "PHP:"
        - PHP.Agent
        - PHP/
        - PHPShell
        - PShlSpy
        - SinoChoper
        - Trojan.ASP
        - Trojan.JSP
        - Trojan.PHP
        - Trojan.VBS
        - VBS.Agent
        - VBS/Agent
        - Webshell
  condition: selection
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: fdf135a2-9241-4f96-a114-bb404948f736
    type: derived

What it detects

This rule flags antivirus detections whose signature strings indicate a web shell or web-based backdoor across multiple server-side script types (ASP, ASPX, JSP, PHP, Perl, VBS) and related “webshell” naming. Attackers often rely on web shells for persistence and remote command execution through HTTP, making these detections high priority even if the malware was blocked. The rule relies on antivirus alert telemetry that includes a signature field matched by specific prefix and substring indicators.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.