Windows Script Executed From a Suspicious Path
Description
Identifies execution of a Windows script from downloads or desktop folders followed by spawning a child process or performing an outgoing network connection to the internet.
Query · eql
sequence with maxspan=5m
[process where event.action == "start" and
process.name in~ ("wscript.exe", "mshta.exe") and
process.args : ("?:\\Users\\*\\Downloads\\*", "?:\\Users\\*\\Desktop\\*", "?:\\Users\\*\\Documents\\*")] as event0
[any where
/* script utility perform an egress connection to the internet */
(event.category == "network" and event.action in ("disconnect_received", "connection_attempted") and
process.name in~ ("wscript.exe", "mshta.exe", "hh.exe", "mmc.exe") and
process.entity_id == event0.process.entity_id and
not cidrmatch(destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24",
"192.0.0.0/29", "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32",
"192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.168.0.0/16",
"100.64.0.0/10", "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1",
"FE80::/10", "FF00::/8")) or
/* script utility spawn a child process */
(event.category == "process" and event.action == "start" and process.parent.name : "explorer.exe" and
process.parent.name in~ ("wscript.exe", "mshta.exe") and process.parent.entity_id == event0.process.entity_id)
]