wscript-powershell-cradle
Multi-stage execution chain: JScript/WScript carrier instantiates WScript.Shell (or Shell.Application), expands environment variables, and spawns powershell.exe with -ExecutionPolicy Bypass and -WindowStyle Hidden to execute a PowerShell payload in a hidden window. The PowerShell stage is typically a download cradle, reflective .NET loader, or inline encoded command.
Why it works. Parent-child telemetry shows wscript.exe → powershell.exe, but the PowerShell command line is often assembled from obfuscated string fragments at runtime, defeating static command-line signatures. The use of -EncodedCommand or environment-variable staging further separates the payload from the carrier.
Variations observed.
- Direct
WshShell.Run("powershell -ep bypass ...") - Environment-variable staging: WScript writes payload to
%TEMP%env var, PowerShell reads it. - WMI hidden spawn (
Win32_Process.CreatewithShowWindow = 0) to avoidWScript.Shell.Runtelemetry.
Observed in
unclassified-js-german-locale-dropper(d3d22298) — bracket-notation COM API assembly + PowerShell C2 cradle.- Sample
6f4de3f9— deobfuscated strings showpowershell,-NoProfile,-WindowStyle Hidden, andAdd-Contentfragments, consistent with a WScript → PowerShell → payload chain. ^[/intel/analyses/6f4de3f972e1acf8ca603ff87b65ab4b92abf303f98b87cc7e822bfd5828d132.html] 37e8fc3692a6(Payment-Swift-TT05294758.js) — WScript →MSXML2.XMLHTTPdownload →powershell.exe -nop -ep bypass -windowstyle hidden -fileexecution chain, part of theitegroup-sbs-droppercluster. ^[/intel/analyses/37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2.html]