Files
splunk-security_content/detections/endpoint/vbscript_execution_using_wscript_app.yml
T

71 lines
2.6 KiB
YAML

author: Teoderick Contreras, Splunk
datamodel:
- Endpoint
date: '2021-10-01'
description: This analytic is to detect a suspicious wscript commandline to execute
vbscript. This technique was seen in several malware to execute malicious vbs file
using wscript application. commonly vbs script is associated to cscript process
and this can be a technique to evade process parent child detections or even some
av script emulation system.
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
id: 35159940-228f-11ec-8a49-acde48001122
known_false_positives: unknown
name: Vbscript Execution Using Wscript App
references:
- https://www.joesandbox.com/analysis/369332/0/html
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name
= "wscript.exe" AND Processes.parent_process = "*//e:vbscript*") OR (Processes.process_name
= "wscript.exe" AND Processes.process = "*//e:vbscript*") by Processes.parent_process_name
Processes.parent_process Processes.process_name Processes.process_id Processes.process
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `vbscript_execution_using_wscript_app_filter`'
tags:
analytic_story:
- FIN7
- Remcos
automated_detection_testing: passed
confidence: 70
context:
- Source:Endpoint
- Stage:Execution
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log
impact: 70
kill_chain_phases:
- Exploitation
message: Process name $process_name$ with commandline $process$ to execute vbsscript
mitre_attack_id:
- T1059.005
- T1059
observable:
- name: dest
role:
- Victim
type: Endpoint
- name: user
role:
- Victim
type: User
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- Endpoint.Processes.dest
- Endpoint.Processes.parent_process
- Endpoint.Processes.parent_process_name
- Endpoint.Processes.process
- Endpoint.Processes.process_id
- Endpoint.Processes.process_name
- Endpoint.Processes.user
- _time
risk_score: 49
security_domain: endpoint
type: TTP
version: 1