Windows Process Creation Matching Mustang Panda Dropper Command-Line and winwsh.exe

Alerts on Windows process creation with temp-based wtaks/winwsh execution and script-launch command-line parameters.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-30
Updated
2026-07-31
title: Windows Process Creation Matching Mustang Panda Dropper Command-Line and winwsh.exe
id: 089fd9de-ec27-4e59-8f8b-688ce50ade28
status: test
description: This rule flags Windows process creation events whose command line contains specific parameters associated with a dropper workflow, including creation of Temp\wtask.exe and use of VBScript targeting a user .txt file with output redirection. It also matches activity where the process image ends with Temp\winwsh.exe. The behavior matters because it can indicate staged execution and dropper-driven persistence or delivery. The detection relies on process creation telemetry capturing both the full Image path and the process CommandLine.
references:
  - https://app.any.run/tasks/7ca5661d-a67b-43ec-98c1-dd7a8103c256/
  - https://app.any.run/tasks/b12cccf3-1c22-4e28-9d3e-c7a6062f3914/
  - https://www.anomali.com/blog/china-based-apt-mustang-panda-targets-minority-groups-public-and-private-sector-organizations
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2019/TA/MustangPanda/proc_creation_win_apt_mustangpanda.yml
author: Florian Roth (Nextron Systems), oscd.community, Huntrule Team
date: 2019-10-30
modified: 2021-11-27
tags:
  - attack.t1587.001
  - attack.resource-development
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_cli:
    - CommandLine|contains:
        - Temp\wtask.exe /create
        - "%windir:~-3,1%%PUBLIC:~-9,1%"
        - '/tn "Security Script '
        - "%windir:~-1,1%"
    - CommandLine|contains|all:
        - /E:vbscript
        - C:\Users\
        - .txt
        - /F
  selection_img:
    Image|endswith: Temp\winwsh.exe
  condition: 1 of selection_*
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: 2d87d610-d760-45ee-a7e6-7a6f2a65de00
    type: derived