Files
splunk-security_content/detections/endpoint/vbscript_execution_using_wscript_app.yml
T
2023-01-25 15:08:29 +01:00

79 lines
2.8 KiB
YAML

name: Vbscript Execution Using Wscript App
id: 35159940-228f-11ec-8a49-acde48001122
version: 1
date: '2021-10-01'
author: Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: This analytic is to detect a suspicious wscript commandline to execute
vbscript. This technique was seen in several malware to execute malicious vbs file
using wscript application. commonly vbs script is associated to cscript process
and this can be a technique to evade process parent child detections or even some
av script emulation system.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name
= "wscript.exe" AND Processes.parent_process = "*//e:vbscript*") OR (Processes.process_name
= "wscript.exe" AND Processes.process = "*//e:vbscript*") by Processes.parent_process_name
Processes.parent_process Processes.process_name Processes.process_id Processes.process
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `vbscript_execution_using_wscript_app_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: unknown
references:
- https://www.joesandbox.com/analysis/369332/0/html
- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat
tags:
analytic_story:
- FIN7
- Remcos
- AsyncRAT
confidence: 70
context:
- Source:Endpoint
- Stage:Execution
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log
impact: 70
kill_chain_phases:
- Exploitation
message: Process name $process_name$ with commandline $process$ to execute vbsscript
mitre_attack_id:
- T1059.005
- T1059
observable:
- name: dest
type: Endpoint
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 49
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint