T1204.002 Malicious File — ATT&CK Technique
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso. Adversaries may employ various forms of Masquerading and Obfuscated Files or Information to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it. While Malicious File frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing.
Detection coverage (50)
- Kapeka Backdoor Loaded Via Rundll32.EXE high
- Microsoft Word Add-In Loaded low
- Microsoft Excel Add-In Loaded low
- Download From Suspicious TLD - Blacklist low
- Suspicious Microsoft Office Child Process - MacOS high
- Download From Suspicious TLD - Whitelist low
- Flash Player Update from Suspicious Location high
- AppLocker Prevented Application or Script from Running medium
- File With Uncommon Extension Created By An Office Application high
- Suspicious Startup Folder Persistence high
- CLR DLL Loaded Via Office Applications medium
- DotNET Assembly DLL Loaded Via Office Application medium
- Remote DLL Load Via Rundll32.EXE medium
- Microsoft Excel Add-In Loaded From Uncommon Location medium
- Microsoft VBA For Outlook Addin Loaded Via Outlook medium
- VBA DLL Loaded Via Office Application high
- GAC DLL Loaded Via Office Applications high
- HackTool - LittleCorporal Generated Maldoc Injection high
- MMC Executing Files with Reversed Extensions Using RTLO Abuse high
- Windows MSIX Package Support Framework AI_STUBS Execution low
- Suspicious Microsoft Office Child Process high
- Suspicious Outlook Child Process high
- Suspicious Binary In User Directory Spawned From Office Application high
- Potential Suspicious Browser Launch From Document Reader Process medium
- Suspicious LNK Command-Line Padding with Whitespace Characters high
- Suspicious WMIC Execution Via Office Process high
- Suspicious WmiPrvSE Child Process high
- New Application in AppCompat informational
- O365 SharePoint Malware Detection
- O365 Threat Intelligence Suspicious File Detected
- Batch File Write to System32
- Cisco NVM - Susp Script From Archive Triggering Network Activity
- Windows AppX Deployment Full Trust Package Installation medium
- Drop IcedID License dat
- Single Letter Process On Endpoint
- Suspicious Process Executed From Container File
- TanStack Supply-Chain Attack Execution Indicators - Windows high
- Windows Advanced Installer MSIX with AI_STUBS Execution
- Windows AppX Deployment Package Installation Success
- Windows AppX Deployment Full Trust Package Installation
- Windows AppX Deployment Unsigned Package Installation
- Windows Binary Execution from an Archive
- Windows Default Cobalt Strike PowerShell Beacon
- Windows Developer-Signed MSIX Package Installation
- Windows EFI Volume Mount Attempt Via Mountvol
- Windows Explorer.exe Spawning PowerShell or Cmd
- Windows Explorer LNK Exploit Process Launch With Padding
- Windows MSIX Package Interaction
- Windows Mustang Panda USB Tool Execution
- Windows NorthStar C2 Agent Execution
Malware using this technique
- TrickBot
- BLINDINGCAN
- Ninja
- Bumblebee
- Bandook
- KONNI
- KOPILUWAK
- ThreatNeedle
- Havoc
- StrongPity
- Pony
- ROAMINGHOUSE
- AppleSeed
- NETWIRE
- SQLRat
- Bad Rabbit
- EnvyScout
- STATICPLUGIN
- Emotet
- Clambling
- Woody RAT
- Squirrelwaffle
- Snip3
- Rifdoor
- CLAIMLOADER
- Mispadu
- RustyWater
- IcedID
- Flagpro
- DarkTortilla
- BeaverTail
- ROKRAT
- SUGARDUMP
- Javali
- PlugX
- Bisonal
- Lumma Stealer
- DarkGate
- Mongall
- SVCReady
- Latrodectus
- Saint Bot
- Chaes
- LODEINFO
- TYPEFRAME
- Bundlore
- Metamorfo
- Heyoka Backdoor
- DnsSystem
- KGH_SPY
Threat actors using this technique
- Prinz Eugen
- SideCopy
- Inception
- Void Manticore
- PROMETHIUM
- APT30
- HEXANE
- Termite
- Rancor
- WIRTE
- PLATINUM
- Evil Corp
- Elderwood
- Kimsuky
- EXOTIC LILY
- admin@338
- Star Blizzard
- Patchwork
- Dragonfly
- Gorgon Group
- APT10
- APT32
- FIN6
- Tonto Team
- Gamaredon Group
- Gallmaker
- Storm-1811
- FIN7
- Sandworm Team
- Machete
- Andariel
- CURIUM
- Sidewinder
- Mustang Panda
- APT35
- APT39
- Contagious Interview
- TA2541
- APT37
- OilRig
- Higaisa
- Ajax Security Team
- APT27
- Tropic Trooper
- TA459
- Aoqin Dragon
- Ferocious Kitten
- The White Company
- Saint Bear
- DarkHydrus