Antivirus Web Shell Signature Matches Across ASP, JSP, PHP, Perl, and VBS

Alerts on AV signatures indicating web shells/backdoors (ASP/JSP/PHP/Perl/VBS/Webshell) to support fast investigation of persistence.

FreeReviewedSigma · High · v5
Category
antivirus
Author
Florian Roth (Nextron Systems), Arnim Rupp (SigmaHQ), DRL 1.1
Published
2018-09-09
Updated
2026-07-31
title: Antivirus Web Shell Signature Matches Across ASP, JSP, PHP, Perl, and VBS
id: 5a4d83a1-ca1d-4527-9adf-f432844c8b46
status: test
description: This rule flags antivirus detections whose signature starts with common web-shell-related families (ASP, JSP, PHP, Perl, and VBS) or contains multiple web shell and backdoor filename patterns. Web shells enable persistent remote execution via a compromised web application, making these alerts high value even when the AV blocks the payload. Telemetry relies on antivirus alert metadata, specifically the reported signature text in the AV event.
references:
  - https://www.nextron-systems.com/?s=antivirus
  - https://github.com/tennc/webshell
  - https://www.virustotal.com/gui/file/bd1d52289203866645e556e2766a21d2275877fbafa056a76fe0cf884b7f8819/detection
  - https://www.virustotal.com/gui/file/308487ed28a3d9abc1fec7ebc812d4b5c07ab025037535421f64c60d3887a3e8/detection
  - https://www.virustotal.com/gui/file/7d3cb8a8ff28f82b07f382789247329ad2d7782a72dde9867941f13266310c80/detection
  - https://www.virustotal.com/gui/file/e841675a4b82250c75273ebf0861245f80c6a1c3d5803c2d995d9d3b18d5c4b5/detection
  - https://www.virustotal.com/gui/file/a80042c61a0372eaa0c2c1e831adf0d13ef09feaf71d1d20b216156269045801/detection
  - https://www.virustotal.com/gui/file/b219f7d3c26f8bad7e175934cd5eda4ddb5e3983503e94ff07d39c0666821b7e/detection
  - https://www.virustotal.com/gui/file/b8702acf32fd651af9f809ed42d15135f842788cd98d81a8e1b154ee2a2b76a2/detection
  - https://www.virustotal.com/gui/file/13ae8bfbc02254b389ab052aba5e1ba169b16a399d9bc4cb7414c4a73cd7dc78/detection
  - https://github.com/SigmaHQ/sigma/blob/master/rules/category/antivirus/av_webshell.yml
author: Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team
date: 2018-09-09
modified: 2026-06-29
tags:
  - attack.persistence
  - attack.t1505.003
logsource:
  category: antivirus
detection:
  selection:
    - Signature|startswith:
        - ASP.
        - IIS/BackDoor
        - JAVA/Backdoor
        - JSP.
        - Perl.
        - PHP.
        - Troj/ASP
        - Troj/JSP
        - Troj/PHP
        - VBS/Uxor
    - Signature|contains:
        - ASP_
        - "ASP:"
        - ASP.Agent
        - ASP/
        - Aspdoor
        - ASPXSpy
        - Backdoor.ASP
        - Backdoor.Java
        - Backdoor.JSP
        - Backdoor.PHP
        - Backdoor.VBS
        - Backdoor/ASP
        - Backdoor/Java
        - Backdoor/JSP
        - Backdoor/PHP
        - Backdoor/VBS
        - C99shell
        - Chopper
        - filebrowser
        - JSP_
        - "JSP:"
        - JSP.Agent
        - JSP/
        - "Perl:"
        - Perl/
        - PHP_
        - "PHP:"
        - PHP.Agent
        - PHP/
        - PHPShell
        - PShlSpy
        - SinoChoper
        - Trojan.ASP
        - Trojan.JSP
        - Trojan.PHP
        - Trojan.VBS
        - VBS.Agent
        - VBS/Agent
        - Webshell
  condition: selection
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: fdf135a2-9241-4f96-a114-bb404948f736
    type: derived