JScript-driven WMI OS-language/sandbox recon before payload execution
Detects execution of WMI or PowerShell queries by HTA, WScript, or CScript processes to gather system information such as OSLanguage, BIOS, or hardware identifiers. This behavior is indicative of environment-awareness checks used by the Casbaneiro/Ousaban banking trojan to identify sandbox or virtualization analysis environments before proceeding with the infection.
Microsoft Sentinel (KQL)

