Files
splunk-security_content/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml
T
2022-03-09 14:43:09 +01:00

79 lines
2.6 KiB
YAML

name: Execute Javascript With Jscript COM CLSID
id: dc64d064-d346-11eb-8588-acde48001122
version: 1
date: '2021-06-22'
author: Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: This analytic will identify suspicious process of cscript.exe where it
tries to execute javascript using jscript.encode CLSID (COM OBJ). This technique
was seen in ransomware (reddot ransomware) where it execute javascript with this
com object with combination of amsi disabling technique.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cscript.exe"
Processes.process="*-e:{F414C262-6AC0-11CF-B6D1-00AA00BBBB58}*" by Processes.parent_process_name
Processes.process_name Processes.process Processes.parent_process Processes.process_id
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `execute_javascript_with_jscript_com_clsid_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the Filesystem responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Filesystem` node.
known_false_positives: unknown
references:
- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/
tags:
analytic_story:
- Ransomware
confidence: 70
context:
- Source:Endpoint
- Stage:Execution
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log
impact: 80
kill_chain_phases:
- Exploitation
message: Suspicious process of cscript.exe with a parent process $parent_process_name$
where it tries to execute javascript using jscript.encode CLSID (COM OBJ), detected
on $dest$ by $user$
mitre_attack_id:
- T1059
- T1059.005
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Endpoint
role:
- Victim
- name: process_id
type: Process
role:
- Attacker
- name: parent_process_name
type: Process Name
role:
- Parent Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.parent_process
- Processes.process_id
- Processes.dest
- Processes.user
risk_score: 56
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint