name: Execute Javascript With Jscript COM CLSID id: dc64d064-d346-11eb-8588-acde48001122 version: 1 date: '2021-06-22' author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint description: This analytic will identify suspicious process of cscript.exe where it tries to execute javascript using jscript.encode CLSID (COM OBJ). This technique was seen in ransomware (reddot ransomware) where it execute javascript with this com object with combination of amsi disabling technique. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cscript.exe" Processes.process="*-e:{F414C262-6AC0-11CF-B6D1-00AA00BBBB58}*" by Processes.parent_process_name Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `execute_javascript_with_jscript_com_clsid_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. known_false_positives: unknown references: - https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ tags: analytic_story: - Ransomware confidence: 70 context: - Source:Endpoint - Stage:Execution dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log impact: 80 kill_chain_phases: - Exploitation message: Suspicious process of cscript.exe with a parent process $parent_process_name$ where it tries to execute javascript using jscript.encode CLSID (COM OBJ), detected on $dest$ by $user$ mitre_attack_id: - T1059 - T1059.005 observable: - name: user type: User role: - Victim - name: dest type: Endpoint role: - Victim - name: process_id type: Process role: - Attacker - name: parent_process_name type: Process Name role: - Parent Process - Attacker product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud required_fields: - _time - Processes.parent_process_name - Processes.process_name - Processes.process - Processes.parent_process - Processes.process_id - Processes.dest - Processes.user risk_score: 56 security_domain: endpoint supported_tas: - Splunk_TA_microsoft_sysmon asset_type: Endpoint