VBScript Payload Stored in Registry

 Original Source: [Sigma source]
Title: VBScript Payload Stored in Registry
Status: test
Description:Detects VBScript content stored into registry keys as seen being used by UNC2452 group
References:
  -https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/
Author: Florian Roth (Nextron Systems)
Date: 2021-03-05
modified:2023-08-17
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1547.001'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains: 'Software\Microsoft\Windows\CurrentVersion'
    Details|contains:
      -'vbscript:'
      -'jscript:'
      -'mshtml,'
      -'RunHTMLApplication'
      -'Execute('
      -'CreateObject'
      -'window.close'

  filter:
    TargetObject|contains: 'Software\Microsoft\Windows\CurrentVersion\Run'
  filter_dotnet:
    Image|endswith: '\msiexec.exe'
    TargetObject|contains: '\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\'
    Details|contains:
      -'\Microsoft.NET\Primary Interop Assemblies\Microsoft.mshtml.dll'
      -'<\Microsoft.mshtml,fileVersion='
      -'_mshtml_dll_'
      -'<\Microsoft.mshtml,culture='

  condition:selection and not 1 of filter*
Falsepositives:
  -Unknown
Level: high