Potential Register_App.Vbs LOLScript Abuse

 Original Source: [Sigma source]
Title: Potential Register_App.Vbs LOLScript Abuse
Status: test
Description:Detects potential abuse of the "register_app.vbs" script that is part of the Windows SDK. The script offers the capability to register new VSS/VDS Provider as a COM+ application. Attackers can use this to install malicious DLLs for persistence and execution.
References:
  -https://twitter.com/sblmsrsn/status/1456613494783160325?s=20
  -https://github.com/microsoft/Windows-classic-samples/blob/7cbd99ac1d2b4a0beffbaba29ea63d024ceff700/Samples/Win7Samples/winbase/vss/vsssampleprovider/register_app.vbs
Author: Austin Songer @austinsonger
Date: 2021-11-05
modified:2022-07-07
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\cscript.exe'
      - '\wscript.exe'
    - OriginalFileName:
      - 'cscript.exe'
      - 'wscript.exe'
  selection_cli:
    CommandLine|contains: '.vbs -register '
  condition:all of selection*
Falsepositives:
  -Other VB scripts that leverage the same starting command line flags
Level: medium