Files
blue-team-tools/rules/windows/process_creation/win_malware_script_dropper.yml
T

34 lines
856 B
YAML

title: WScript or CScript Dropper
status: experimental
description: Detects wscript/cscript executions of scripts located in user directories
author: Margaritis Dimitrios (idea), Florian Roth (rule)
logsource:
category: process_creation
product: windows
detection:
selection:
Image:
- '*\wscript.exe'
- '*\cscript.exe'
CommandLine:
- '* C:\Users\*.jse *'
- '* C:\Users\*.vbe *'
- '* C:\Users\*.js *'
- '* C:\Users\*.vba *'
- '* C:\Users\*.vbs *'
- '* C:\ProgramData\*.jse *'
- '* C:\ProgramData\*.vbe *'
- '* C:\ProgramData\*.js *'
- '* C:\ProgramData\*.vba *'
- '* C:\ProgramData\*.vbs *'
falsepositive:
ParentImage: '*\winzip*'
condition: selection
fields:
- CommandLine
- ParentCommandLine
falsepositives:
- Winzip
- Other self-extractors
level: high