Bringen Sie Freizeit-Werkzeug an!
Drücken Sie Kopie-Taste und fügen Sie in Ihrem Blog oder Ihrer Website.
(Wechseln Sie bitte in den 'HTML'-Modus bei der Buchung in Ihrem Blog. Beispiele: WordPress Beispiel, Blogger Beispiel)
STARWHALE, Software S1037 | MITRE ATT CK® STARWHALE is Windows Script File (WSF) backdoor that has been used by MuddyWater, possibly since at least November 2021; there is also a STARWHALE variant written in Golang with similar capabilities
Qakbot Malware: Exploring Its Diverse Distribution Methods - Cyble This archive file includes a script with a wsf extension that is executed using the Windows system file WScript exe The script then downloads a DLL file containing the Qakbot malware, which is subsequently run using rundll32 exe
Windows: Potential Manage-bde. wsf Abuse To Proxy Execution Detects potential abuse of the "manage-bde wsf" script as a LOLBIN to proxy execution This rule is adapted from https: github com SigmaHQ sigma blob master rules windows process_creation proc_creation_win_lolbin_manage_bde yml
Command and Scripting Interpreter: Visual Basic, Sub-technique T1059 . . . Monitor for events associated with VB execution, such as Office applications spawning processes, usage of the Windows Script Host (typically cscript exe or wscript exe), file activity involving VB payloads or scripts, or loading of modules associated with VB languages (ex: vbscript dll)