T1059.005 Visual Basic — ATT&CK Technique
Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as Component Object Model and the Native API through the Windows API. Although tagged as legacy with no planned future evolutions, VB is integrated and supported in the .NET Framework and cross-platform .NET Core. Derivative languages based on VB have also been created, such as Visual Basic for Applications (VBA) and VBScript. VBA is an event-driven programming language built into Microsoft Office, as well as several third-party applications. VBA enables documents to contain macros used to automate the execution of tasks and other functionality on the host. VBScript is a default scripting language on Windows hosts and can also be used in place of JavaScript on HTML Application (HTA) webpages served to Internet Explorer (though most modern browsers do not come with VBScript support). Adversaries may use VB payloads to execute malicious commands. Common malicious usage includes automating execution of behaviors with VBScript or embedding VBA content into Spearphishing Attachment payloads (which may also involve Mark-of-the-Web Bypass to enable execution).
Detection coverage (36)
- Axios NPM Compromise Indicators - Windows high
- WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript medium
- AppLocker Prevented Application or Script from Running medium
- HackTool - CACTUSTORCH Remote Thread Creation high
- WScript or CScript Dropper - File high
- HackTool - NetExec File Indicators high
- Adwind RAT / JRAT File Artifact high
- MMC Loading Script Engines DLLs medium
- Registry Modification Attempt Via VBScript - PowerShell medium
- Uncommon Child Process Of BgInfo.EXE medium
- Suspicious Child Process Of BgInfo.EXE high
- Csc.EXE Execution Form Potentially Suspicious Parent high
- HTML Help HH.EXE Suspicious Child Process high
- Suspicious HH.EXE Execution high
- HackTool - Koadic Execution high
- Potential Reconnaissance Activity Via GatherNetworkInfo.VBS medium
- Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS high
- Windows Shell/Scripting Processes Spawning Suspicious Programs high
- Registry Modification Attempt Via VBScript medium
- XSL Script Execution Via WMIC.EXE medium
- Potential Remote SquiblyTwo Technique Execution high
- Cscript/Wscript Uncommon Script Extension Execution high
- Potential Dropper Script Execution Via WScript/CScript/MSHTA medium
- Registry Tampering by Potentially Suspicious Processes medium
- Suspicious Scripting in a WMI Consumer high
- Potential QBot Activity critical
- Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
- Cisco NVM - Susp Script From Archive Triggering Network Activity
- Execute Javascript With Jscript COM CLSID
- Adwind RAT / JRAT high
- Vbscript Execution Using Wscript App
- Windows Outlook Macro Created by Suspicious Process
- Suspicious Process DNS Query Known Abuse Web Services
- Suspicious Process With Discord DNS Query
- Potential APT10 Cloud Hopper Activity high
- AppLocker Application Would Have Been Blocked medium
Malware using this technique
- Bumblebee
- Exaramel for Windows
- Bandook
- Smoke Loader
- TAMECAT
- Ursnif
- NETWIRE
- Emotet
- Squirrelwaffle
- ShrinkLocker
- Snip3
- WhisperGate
- Mispadu
- IcedID
- PowerShower
- CHIMNEYSWEEP
- IPsec Helper
- Flagpro
- KeyBoy
- Pteranodon
- ROKRAT
- Javali
- Bisonal
- Xbash
- SUNBURST
- DarkGate
- NanHaiShu
- SVCReady
- Ferocious
- Saint Bot
- BabyShark
- Melcoz
- Chaes
- TYPEFRAME
- QUADAGENT
- Metamorfo
- Kerrdown
- VBShower
- StoneDrill
- OopsIE
- BackConfig
- Grandoreiro
- Sibot
- LunarMail
- Cobalt Strike
- JCry
- REvil
- OSX_OCEANLOTUS.D
- NanoCore
- Koadic
Threat actors using this technique
- APT38
- Inception
- HEXANE
- Rancor
- WIRTE
- SideCopy
- Kimsuky
- Patchwork
- Gorgon Group
- APT32
- MuddyWater
- APT-C-36
- Gamaredon Group
- FIN7
- Sandworm Team
- Machete
- Sidewinder
- Mustang Panda
- APT35
- APT39
- Contagious Interview
- TA2541
- APT37
- OilRig
- Higaisa
- TA459
- Confucius
- APT40
- Turla
- TA505
- RedCurl
- MirrorFace
- BRONZE BUTLER
- APT33
- LazyScripter
- Windshift
- Malteiro
- APT42
- Lazarus Group
- Earth Lusca
- FIN4
- Silence
- Cobalt Group
- Molerats
- Transparent Tribe
- FIN13