Suspicious Mshta.EXE Execution Patterns

 Original Source: [Sigma source]
Title: Suspicious Mshta.EXE Execution Patterns
Status: test
Description:Detects suspicious mshta process execution patterns
References:
  -https://en.wikipedia.org/wiki/HTML_Application
  -https://www.echotrail.io/insights/search/mshta.exe
  -https://app.any.run/tasks/34221348-072d-4b70-93f3-aa71f6ebecad/
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2021-07-17
modified:2023-02-21
Tags:
  • -'attack.execution'
  • -'attack.t1106'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\mshta.exe' OriginalFileName:'MSHTA.EXE'   selection_susp:
    ParentImage|endswith:
      -'\cmd.exe'
      -'\cscript.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'
      -'\wscript.exe'

    CommandLine|contains:
      -'\AppData\Local\'
      -'C:\ProgramData\'
      -'C:\Users\Public\'
      -'C:\Windows\Temp\'

  filter_img:
    - Image|startswith:
      - 'C:\Windows\System32\'
      - 'C:\Windows\SysWOW64\'
    - CommandLine|contains:
      - '.htm'
      - '.hta'
    - CommandLine|endswith:
      - 'mshta.exe'
      - 'mshta'
  condition:all of selection_* or (selection_img and not filter_img)
Falsepositives:
  -Unknown
Level: high