Webserver POST Uploads Java Web Shell Files in SAP NetViewer

Alerts on POST requests to /irj/ endpoints uploading Java extension files with octet-stream content type.

FreeReviewedSigma · High · v5
Category
webserver
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-05-14
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags HTTP POST requests where the response content type indicates raw binary data (application/octet-stream) and the requested URI path targets Java web shell file types (.jsp, .java, .class) within /irj/. Attackers often use web shell uploads to establish persistent remote code execution capability. The detection relies on webserver request telemetry, including HTTP method, Content-Type, and the URI stem patterns from incoming requests.

Related detections9 linkedT1505.003 — drag to rearrange
Suspicious SD-WAN Compromise JSP Webshell Access
Malicious AquaShell Webshell Access on Cisco Secure Email Gateway by UAT-9686
Malicious IIS Worker Process Spawning Command Shell Reconnaissance
Malicious StyleSmuggler (CVE-2026-75650) Web Shell Dropped In Magento Product Image Cache (via file_event)
Suspicious Web Shell File Written to IIS wwwroot Directory
Possible Citrix ShareFile Unauthenticated Upload Path Traversal Webshell (CVE-2023-24489) (via webserver)
Possible Unauthenticated Admin Creation in Dynamicweb CVE-2022-25369
Possible DotCMS Path Traversal Webshell Upload via content API CVE-2022-26352
Possible Avaya Aura Device Services WebDAV PHP Webshell Upload via PhoneBackup (via webserver)
Webserver POST Uploads Java Web Shell Files in SAP NetViewer
Pivot detection · T1505.003 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.