FORENSIA

ATT&CK · T1059.005 · sub-technique

Visual Basic

Tactics: execution

About

Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as Component Object Model and the Native API through the Windows API. Although tagged as legacy with no planned future evolutions, VB is integrated and supported in the .NET Framework and cross-platform .NET Core. Derivative languages based on VB have also been created, such as Visual Basic for Applications (VBA) and VBScript. VBA is an event-driven programming language built into Microsoft Office, as well as several third-party applications. VBA enables documents to contain macros used to automate the execution of tasks and other functionality on the host. VBScript is a default scripting language on Windows hosts and can also be used in place of JavaScript on HTML Application (HTA) webpages served to Internet Explorer (though most modern browsers do not come with VBScript support). Adversaries may use VB payloads to execute malicious commands. Common malicious usage includes automating execution of behaviors with VBScript or embedding VBA content into Spearphishing Attachment payloads (which may also involve Mark-of-the-Web Bypass to enable execution).

Platforms: Linux, macOS, WindowsParent: T1059 Command and Scripting InterpreterMITRE ATT&CK ↗

Used by actors

46 known groups

Software

69 malware/tools implement this

PteranodonCobalt StrikeHelminthNETWIREPOWERSTATSSmoke LoaderNanHaiShuBandookROKRATComnieKoadicTYPEFRAMEOopsIEBisonalQUADAGENTjRATRemcosNanoCoreXbashExaramel for WindowsOSX_OCEANLOTUS.DEmotetAstarothRemexiStoneDrillUrsnifKeyBoyJCryBabySharkPoetRATPowerShowerVBShowerLokibotMetamorfoRamsayBackConfigGoopyIcedIDREvilJavaliMelcozGrandoreiroSUNBURSTLookBackKerrdownSibotChaesJSS LoaderQakBotKOCTOPUSFerociousWhisperGateDonutFlagproDanBotSaint BotSquirrelwaffleSTARWHALEBumblebeeSVCReadySnip3DarkGateMispaduIPsec HelperLunarMailCHIMNEYSWEEPShrinkLockerTAMECATSystemBC

Corpus indicators tagged with this technique

457 indicators in the corpus carry T1059.005.

IndicatorTypeFamilySevSrc
7d6ee3c6ff8f70b1817aaec82aff1d2babe0b62cafef3975262644743afc0cb8hash801
0ba93109757776a44de9d8c88baa4963hash801
808e7154b7af2bc7a4b28d577297c55f77221c355191cbe00f9f1810b6d4a619hashphishing802
4c0d9b802c075be79e9edb52d88f8dd72e6904f5c58267213745818470945c78hashphishing802
8e1624d110c090ff57d4b493a9107c66hash803
887ec87e4a19759cad25d4bc0956d2b965d3041dhash801
b032d4ec4e24714f59e853da9b6e63794aacdbcbhashphishing803
4ce45e016a304d813e67b29a08265b2101c2e15a09ace5de6539cad02567affesha256supply_chain801
ced6b0f4441085bb9c54a32da9ab4ba14c6e21daf6e34fd61d54923f87baacd0hashphishing803
a2c6e01001c62f6198e31a9d603977c6hash802
d5e9288693aa745dc89368deac677e7ea1ec81e663283af30838cdae189b7a7ehashphishing802
1794369214b7f62e70a0485e61335c61hash803
02bb20455cc592a69c080abac770ce90hash801
31037a42ca048e06e69a78f55bc2eff5hash801
64c7dd0a3a3ae49977ac05913d3878000cce14e5d8c1ee05b782bdfd648bde91sha256801
ad10ff9043d6f327045943635fcbd0c5918acb79dc998db92ee4c7dee5224710sha256801
164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3sha256supply_chain801
50ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdfsha256supply_chain801
4c9f271242f61f1a31b8146305e9a7ed512c521445d4f7a7a901e301307add3dsha256801
f6669bd504ce6b0e303be7ee47f2ebbc062989c88c41f0a3f436044a24869798sha256supply_chain801
5864a697bd7b339f56b05405f29a097cd027cafdcc4e63c2aaeccccbf930605fsha256801
c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2sha256supply_chain801
282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990sha256supply_chain801
d3ebce2f05fe91a8260e87fd11a6ea17c156703d081b3f91d9bbe5fd6aeedc10hashphishing802
bb10adac5b0124efedfe71102c1d5638135ec9e1cde8c8cb3353c5ed91bb9f81hashphishing802
37e065585c573ecc082aacbfd31564ebhashphishing803
c099f965144bccd0b590f946659fc3c0747c54aef505b6caaca9078712f455fbsha256801
31f27fdc14505e0cebe360579e1ba0326762cbe0948e50b5f920da51fdef1b51hashphishing803
17832aa629524ef6e8d8d6e9b6b902a8d324b559e3c36dbd0e221ab1690be871sha256supply_chain801
2c6f05f1f309d89b2236e6c8b59c88f9hash801

Showing the top 30 by severity of 457.