AN1464
Analytic 1464
Windows
Execution of PubPrn.vbs via cscript.exe using the 'script:' moniker to load and execute a remote .sct scriptlet file, bypassing signature validation and proxying remote payloads through a signed Microsoft script host.
WinEventLog:Sysmon
EventCode=1
WinEventLog:PowerShell
EventCode=4103, 4104, 4105, 4106
WinEventLog:Sysmon
EventCode=3, 22
WinEventLog:Sysmon
EventCode=7
[CommandLineRegex]
Detects 'script:' moniker with HTTP/HTTPS URI as argument to pubprn.vbs
[ParentProcessName]
May vary between cscript.exe, wscript.exe, or cmd.exe depending on execution method
[NetworkDestinationDomain]
Used to detect external domains being contacted for remote scriptlet execution
[TimeWindow]
Maximum allowed time delta between pubprn.vbs invocation and network connection or child process