Remotely Hosted HTA File Executed Via Mshta.EXE

 Original Source: [Sigma source]
Title: Remotely Hosted HTA File Executed Via Mshta.EXE
Status: test
Description:Detects execution of the "mshta" utility with an argument containing the "http" keyword, which could indicate that an attacker is executing a remotely hosted malicious hta file
References:
  -https://www.trendmicro.com/en_us/research/22/e/avoslocker-ransomware-variant-abuses-driver-file-to-disable-anti-Virus-scans-log4shell.html
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-08
modified:2023-02-06
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1218.005'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\mshta.exe' OriginalFileName:'MSHTA.EXE'   selection_cli:
    CommandLine|contains:
      -'http://'
      -'https://'
      -'ftp://'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high