Monitor for events associated with vb execution, such as office applications spawning processes, usage of the windows script host (typically cscript. exe or wscript. exe), file activity involving vb รขโ‚ฌยฆ Detects potential abuse of the manage-bde. wsf script as a lolbin to proxy execution. This rule is adapted from รขโ‚ฌยฆ

Common uses include hosting malicious scripts on websites as part of a drive-by compromise or downloading and executing these script files as secondary payloads. Starwhale is windows script file (wsf) backdoor that has been used by muddywater, possibly since at least november 2021; There is also a starwhale variant written in golang with similar รขโ‚ฌยฆ

๐Ÿ”— Related Articles You Might Like:

Iluvl3x Leaked Of What Is A Leakage Blake Green Nude