Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0528 — Detecting Remote Script Proxy Execution via PubPrn.vbs
DET0528

Detecting Remote Script Proxy Execution via PubPrn.vbs

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1464 Analytic 1464
Windows

Execution of PubPrn.vbs via cscript.exe using the 'script:' moniker to load and execute a remote .sct scriptlet file, bypassing signature validation and proxying remote payloads through a signed Microsoft script host.

WinEventLog:Sysmon EventCode=1 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=7
[CommandLineRegex] Detects 'script:' moniker with HTTP/HTTPS URI as argument to pubprn.vbs
[ParentProcessName] May vary between cscript.exe, wscript.exe, or cmd.exe depending on execution method
[NetworkDestinationDomain] Used to detect external domains being contacted for remote scriptlet execution
[TimeWindow] Maximum allowed time delta between pubprn.vbs invocation and network connection or child process

Detected Techniques

1

Stealth (1)

Details

MITRE ID
DET0528
STIX ID
x-mitre-detection-strategy--4e2e06c5-a7bd-40d9-af9b-99fdfe725360
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.