Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.005 Mshta |
MalwarePteranodon | Pteranodon can use mshta.exe to execute an HTA file hosted on a remote server. |
| T1218.005 Mshta |
MalwareLumma Stealer | Lumma Stealer has used mshta.exe to execute additional content. |
| T1218.005 Mshta |
MalwareXbash | Xbash can use mshta for executing scripts. |
| T1218.005 Mshta |
MalwareNanHaiShu | NanHaiShu uses mshta.exe to load its program and files. |
| T1218.005 Mshta |
MalwareMetamorfo | Metamorfo has used mshta.exe to execute a HTA payload. |
| T1218.005 Mshta |
MalwareSibot | Sibot has been executed via MSHTA application. |
| T1218.005 Mshta |
MalwareRevenge RAT | Revenge RAT uses mshta.exe to run malicious scripts on the system. |
| T1218.005 Mshta |
MalwareBabyShark | BabyShark has used mshta.exe to download and execute applications from a remote server. |
| T1218.005 Mshta |
MalwarePOWERSTATS | POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts. |
| T1218.005 Mshta |
ToolCovenant | Covenant can create HTA files to install Grunt listeners. |
| T1218.005 Mshta |
ToolKoadic | Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence. |
| T1218.007 Msiexec |
MalwareRCSession | RCSession has the ability to execute inside the msiexec.exe process. |
| T1218.007 Msiexec |
MalwareTsundere Botnet | Tsundere Botnet has been distributed via an MSI installer. |
| T1218.007 Msiexec |
MalwareFlawedAmmyy | FlawedAmmyy has been installed via `msiexec.exe`. |
| T1218.007 Msiexec |
MalwareRaspberry Robin | Raspberry Robin uses msiexec.exe for post-installation communication to command and control infrastructure. Msiexec.exe is executed referencing a remote resource for second-stage payload retrieval and execution. |
| T1218.007 Msiexec |
MalwareMispadu | Mispadu has been installed via MSI installer. |
| T1218.007 Msiexec |
MalwareIcedID | IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application. IcedID has also used msiexec.exe to deploy the IcedID loader. |
| T1218.007 Msiexec |
MalwareRagnar Locker | Ragnar Locker has been delivered as an unsigned MSI package that was executed with |
| T1218.007 Msiexec |
MalwareJavali | Javali has used the MSI installer to download and execute malicious payloads. |
| T1218.007 Msiexec |
MalwareLatrodectus | Latrodectus has called `msiexec` to install remotely-hosted MSI files. |
| T1218.007 Msiexec |
MalwareChaes | Chaes has used .MSI files as an initial way to start the infection chain. |
| T1218.007 Msiexec |
MalwareMetamorfo | Metamorfo has used MsiExec.exe to automatically execute files. |
| T1218.007 Msiexec |
MalwareRedLine Stealer | RedLine Stealer has been installed via MSI Installer. |
| T1218.007 Msiexec |
MalwareGrandoreiro | Grandoreiro can use MSI files to execute DLLs. |
| T1218.007 Msiexec |
MalwareDEADEYE | DEADEYE can use `msiexec.exe` for execution of malicious DLL. |
| T1218.007 Msiexec |
MalwareClop | Clop can use msiexec.exe to disable security tools on the system. |
| T1218.007 Msiexec |
MalwareMelcoz | Melcoz can use MSI files with embedded VBScript for execution. |
| T1218.007 Msiexec |
MalwareMaze | Maze has delivered components for its ransomware attacks using MSI files, some of which have been executed from the command-line using |
| T1218.007 Msiexec |
MalwareAppleJeus | AppleJeus has been installed via MSI installer. |
| T1218.007 Msiexec |
MalwareQakBot | QakBot can use MSIExec to spawn multiple cmd.exe processes. |
| T1218.007 Msiexec |
MalwareDOWNIISSA | DOWNIISSA can create an instance of msiexec.exe and inject LODEINFO shellcode into the memory of the process. |
| T1218.007 Msiexec |
MalwareLoudMiner | LoudMiner used an MSI installer to install the virtualization software. |
| T1218.007 Msiexec |
ToolRemoteUtilities | RemoteUtilities can use Msiexec to install a service. |
| T1218.007 Msiexec |
MalwareDuqu | Duqu has used |
| T1218.008 Odbcconf |
MalwareBumblebee | Bumblebee can use `odbcconf.exe` to run DLLs on targeted hosts. |
| T1218.008 Odbcconf |
MalwareRaspberry Robin | Raspberry Robin uses the Windows utility odbcconf.exe to execute malicious commands, using the |
| T1218.009 Regsvcs/Regasm |
MalwareAgent Tesla | Agent Tesla has dropped RegAsm.exe onto systems for performing malicious activity. |
| T1218.010 Regsvr32 |
MalwareOrz | Some Orz versions have an embedded DLL known as MockDll that uses Process Hollowing and regsvr32 to execute another payload. |
| T1218.010 Regsvr32 |
MalwareTONESHELL | TONESHELL has used regsvr32.exe to execute the windows `DLLRegisterServer` function. |
| T1218.010 Regsvr32 |
MalwareAppleSeed | AppleSeed can call regsvr32.exe for execution. |
| T1218.010 Regsvr32 |
MalwareEmotet | Emotet uses RegSvr32 to execute the DLL payload. |
| T1218.010 Regsvr32 |
MalwareSquirrelwaffle | Squirrelwaffle has been executed using `regsvr32.exe`. |
| T1218.010 Regsvr32 |
MalwareRaspberry Robin | Raspberry Robin uses regsvr32.exe execution without any command line parameters for command and control requests to IP addresses associated with Tor nodes. |
| T1218.010 Regsvr32 |
MalwareRagnar Locker | Ragnar Locker has used regsvr32.exe to execute components of VirtualBox. |
| T1218.010 Regsvr32 |
MalwareHi-Zor | Hi-Zor executes using regsvr32.exe called from the Registry Run Keys / Startup Folder persistence mechanism. |
| T1218.010 Regsvr32 |
MalwareXbash | Xbash can use regsvr32 for executing scripts. |
| T1218.010 Regsvr32 |
MalwareSaint Bot | Saint Bot has used `regsvr32` to execute scripts. |
| T1218.010 Regsvr32 |
MalwareEVILNUM | EVILNUM can run a remote scriptlet that drops a file and executes it via regsvr32.exe. |
| T1218.010 Regsvr32 |
MalwareMori | Mori can use `regsvr32.exe` for DLL execution. |
| T1218.010 Regsvr32 |
MalwareRogueRobin | RogueRobin uses regsvr32.exe to run a .sct file for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.