Suspicious PHP File Written to FreePBX Custom Firmware Directory (via file_event)

PremiumReviewedSigma · High · v1
Product
linux
Category
file_event
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects creation of a PHP file inside the FreePBX tftpboot custom firmware directory. The CVE-2025-57819 file upload flaw drops PHP webshells to this path which normally holds only firmware binaries. A PHP file in this location indicates webshell deployment.

Related detections9 linkedT1505.003 — drag to rearrange
Possible Ivanti EPMM In-Memory Java Webshell Access via mifs 403.jsp
Malicious Command Execution Spawned by SharePoint w3wp Worker Process
Suspicious ToolShell Webshell Written to SharePoint Layouts Directory
Suspicious Webshell Deployment in DNN DesktopModules Directory
Suspicious TOLLBOOTH Webshell URI Access
Suspicious Child Process Spawned by IIS Worker Process w3wp
Suspicious Web Shell Spawned via Python or PHP Built-in Server
Suspicious TOLLBOOTH IIS Module Files in Windows Temp
Possible Ivanti Connect Secure Webshell Access
Suspicious PHP File Written to FreePBX Custom Firmware Directory (via file_event)
Pivot detection · T1505.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.