name: Execute Javascript With Jscript COM CLSID id: dc64d064-d346-11eb-8588-acde48001122 version: 1 date: '2021-06-22' author: Teoderick Contreras, Splunk status: production type: TTP description: This analytic will identify suspicious process of cscript.exe where it tries to execute javascript using jscript.encode CLSID (COM OBJ). This technique was seen in ransomware (reddot ransomware) where it execute javascript with this com object with combination of amsi disabling technique. data_source: - Sysmon Event ID 1 search: selection1: CommandLine: '*-e:{F414C262-6AC0-11CF-B6D1-00AA00BBBB58}*' Image|endswith: cscript.exe condition: selection1 how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. known_false_positives: unknown references: - https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ tags: analytic_story: - Ransomware asset_type: Endpoint confidence: 70 impact: 80 message: Suspicious process of cscript.exe with a parent process $parent_process_name$ where it tries to execute javascript using jscript.encode CLSID (COM OBJ), detected on $dest$ by $user$ mitre_attack_id: - T1059 - T1059.005 observable: - name: user type: User role: - Victim - name: dest type: Endpoint role: - Victim - name: process_id type: Process role: - Attacker - name: parent_process_name type: Process Name role: - Parent Process - Attacker product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud risk_score: 56 security_domain: endpoint tests: - name: True Positive Test attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog