Windows Process Creation: China Chopper Webshell Command Pattern via W3WP

Flags w3wp.exe-launched commands matching China Chopper webshell execution patterns in Windows process creation logs.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), MSTI (query) (SigmaHQ), DRL 1.1
Published
2022-10-01
Updated
2026-07-30

ATT&CK techniques

Persistence → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule matches process creation events where w3wp.exe is the originating or parent process and the command line contains webshell-style execution strings consistent with China Chopper (tiny ASPX) webshell activity. Attackers commonly use webshells to run arbitrary commands in the context of the IIS worker process, enabling persistence and post-compromise discovery. Detection relies on Windows process_creation telemetry, using Image/ParentImage ending with w3wp.exe and specific command-line substrings indicating interactive command execution.

Related detections9 linkedT1505.003 — drag to rearrange
Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands
Windows Webshell Recon Command-Line Keywords via Web Server Processes
Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
Cisco AAA discovery via show/dir commands
Suspicious SD-WAN Compromise JSP Webshell Access
Malicious AquaShell Webshell Access on Cisco Secure Email Gateway by UAT-9686
Suspicious Domain Controller Enumeration via Nltest by DeadLock Ransomware
Malicious IIS Worker Process Spawning Command Shell Reconnaissance
Malicious StyleSmuggler (CVE-2026-75650) Web Shell Dropped In Magento Product Image Cache (via file_event)
Windows Process Creation: China Chopper Webshell Command Pattern via W3WP
Pivot detection · T1505.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.