<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Script-Dropper — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/script-dropper/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 02 Jan 2024 12:00:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/script-dropper/feed.xml" rel="self" type="application/rss+xml"/><item><title>WScript or CScript Dropper</title><link>https://feed.craftedsignal.io/briefs/2024-01-cscript-wscript-dropper/</link><pubDate>Tue, 02 Jan 2024 12:00:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2024-01-cscript-wscript-dropper/</guid><description>The WScript or CScript Dropper technique involves using cscript.exe or wscript.exe to write malicious script files (js, jse, vba, vbe, vbs, wsf, wsh) to suspicious locations on a Windows system for later execution.</description><content:encoded><![CDATA[<p>The WScript or CScript Dropper technique is a method employed by attackers to introduce malicious script files into a system. It leverages the built-in Windows scripting hosts, <code>cscript.exe</code> and <code>wscript.exe</code>, to write files with extensions commonly associated with scripting languages (e.g., <code>.js</code>, <code>.vbs</code>, <code>.wsf</code>). These scripts are often written to temporary or user-accessible directories, such as <code>\Temp\</code>, <code>\AppData\</code>, or <code>\Startup\</code>, where they can be executed later, either manually or…</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>script-dropper</category><category>file-creation</category><category>windows</category></item></channel></rss>