Suspicious Scripting in a WMI Consumer

 Original Source: [Sigma source]
Title: Suspicious Scripting in a WMI Consumer
Status: test
Description:Detects suspicious commands that are related to scripting/powershell in WMI Event Consumers
References:
  -https://in.security/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/
  -https://github.com/Neo23x0/signature-base/blob/615bf1f6bac3c1bdc417025c40c073e6c2771a76/yara/gen_susp_lnk_files.yar#L19
  -https://github.com/RiccardoAncarani/LiquidSnake
Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro
Date: 2019-04-15
modified:2023-09-09
Tags:
  • -'attack.execution'
  • -'attack.t1059.005'
Logsource:
  • product: windows
  • category: wmi_event
Detection:
  selection_destination:
    - Destination|contains|all:
      - 'new-object'
      - 'net.webclient'
      - '.downloadstring'
    - Destination|contains|all:
      - 'new-object'
      - 'net.webclient'
      - '.downloadfile'
    - Destination|contains:
      - ' iex('
      - ' -nop '
      - ' -noprofile '
      - ' -decode '
      - ' -enc '
      - 'WScript.Shell'
      - 'System.Security.Cryptography.FromBase64Transform'
  condition:selection_destination
Falsepositives:
  -Legitimate administrative scripts
Level: high