Files
splunk-security_content/dev/endpoint/execute_javascript_with_jscript_com_clsid.yml
T
2023-01-20 13:24:15 +01:00

67 lines
2.0 KiB
YAML

name: Execute Javascript With Jscript COM CLSID
id: dc64d064-d346-11eb-8588-acde48001122
version: 1
date: '2021-06-22'
author: Teoderick Contreras, Splunk
status: production
type: TTP
description: This analytic will identify suspicious process of cscript.exe where it
tries to execute javascript using jscript.encode CLSID (COM OBJ). This technique
was seen in ransomware (reddot ransomware) where it execute javascript with this
com object with combination of amsi disabling technique.
data_source:
- Sysmon Event ID 1
search:
selection1:
CommandLine: '*-e:{F414C262-6AC0-11CF-B6D1-00AA00BBBB58}*'
Image|endswith: cscript.exe
condition: selection1
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the Filesystem responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Filesystem` node.
known_false_positives: unknown
references:
- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/
tags:
analytic_story:
- Ransomware
asset_type: Endpoint
confidence: 70
impact: 80
message: Suspicious process of cscript.exe with a parent process $parent_process_name$
where it tries to execute javascript using jscript.encode CLSID (COM OBJ), detected
on $dest$ by $user$
mitre_attack_id:
- T1059
- T1059.005
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Endpoint
role:
- Victim
- name: process_id
type: Process
role:
- Attacker
- name: parent_process_name
type: Process Name
role:
- Parent Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 56
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/data2/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog