FakeUpdates/SocGholish Activity
Description
Detects initial execution of FakeUpdates/SocGholish malware via wscript that later executes commands via cmd or powershell.
Query · sigma
selection: ParentImage|endswith: \wscript.exe ParentCommandLine|contains|all: - \AppData\Local\Temp - .zip - update - .js ParentCommandLine|contains: - Chrome - Edge - Firefox - Opera - Brave - Vivaldi Image|endswith: - \cmd.exe - \powershell.exe - \pwsh.exe condition: selection
Known false positives
- Unlikely