This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Register_App.Vbs LOLScript Abuse
Original Source:
[Sigma source]
Title:
Potential Register_App.Vbs LOLScript Abuse
Status:
test
Description:
Detects potential abuse of the "register_app.vbs" script that is part of the Windows SDK. The script offers the capability to register new VSS/VDS Provider as a COM+ application. Attackers can use this to install malicious DLLs for persistence and execution.
References:
-https://twitter.com/sblmsrsn/status/1456613494783160325?s=20
-https://github.com/microsoft/Windows-classic-samples/blob/7cbd99ac1d2b4a0beffbaba29ea63d024ceff700/Samples/Win7Samples/winbase/vss/vsssampleprovider/register_app.vbs
Author:
Austin Songer @austinsonger
Date:
2021-11-05
modified:
2022-07-07
Tags:
-'attack.stealth'
-'attack.t1218'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
- Image|endswith
:
- '\cscript.exe'
- '\wscript.exe'
- OriginalFileName
:
- 'cscript.exe'
- 'wscript.exe'
selection_cli:
CommandLine|contains
:
'.vbs -register '
condition
:
all of selection*
Falsepositives:
-Other VB scripts that leverage the same starting command line flags
Level:
medium