Legitimate Application Dropped Script

 Original Source: [Sigma source]
Title: Legitimate Application Dropped Script
Status: test
Description:Detects LOLBINs and applications that should not legitimately drop script files to disk. This may indicate malware staging or abuse of a trusted binary for script-based code execution.
References:
  -https://github.com/Neo23x0/sysmon-config/blob/3f808d9c022c507aae21a9346afba4a59dd533b9/sysmonconfig-export-block.xml#L1326
  -https://dmpdump.github.io/posts/TelegramRat/
  -https://www.virustotal.com/gui/file/a0d5b30578acd1df9139e7a8a4bfc659dc2cf48f4dc0c5804b70890adeb9fa21/behavior
Author: frack113, Florian Roth (Nextron Systems)
Date: 2022-08-21
modified:2026-05-11
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith:
      -'\eqnedt32.exe'
      -'\wordpad.exe'
      -'\wordview.exe'
      -'\certutil.exe'
      -'\certoc.exe'
      -'\CertReq.exe'
      -'\Desktopimgdownldr.exe'
      -'\esentutl.exe'
      -'\mshta.exe'
      -'\AcroRd32.exe'
      -'\RdrCEF.exe'
      -'\hh.exe'
      -'\finger.exe'

    TargetFilename|endswith:
      -'.bat'
      -'.chm'
      -'.csproj'
      -'.hta'
      -'.js'
      -'.jse'
      -'.proj'
      -'.ps1'
      -'.py'
      -'.scf'
      -'.vbe'
      -'.vbs'
      -'.wsf'
      -'.wsh'

  filter_main_mshta:
    Image|endswith: '\mshta.exe'
    TargetFilename|endswith: '.hta'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high