Visual Basic

T1059.005

Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org

About this technique

Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as Component Object Model and the Native API through the Windows API. Although tagged as legacy with no planned future evolutions, VB is integrated and supported in the .NET Framework and cross-platform .NET Core.

Derivative languages based on VB have also been created, such as Visual Basic for Applications (VBA) and VBScript. VBA is an event-driven programming language built into Microsoft Office, as well as several third-party applications. VBA enables documents to contain macros used to automate the execution of tasks and other functionality on the host. VBScript is a default scripting language on Windows hosts and can also be used in place of JavaScript on HTML Application (HTA) webpages served to Internet Explorer (though most modern browsers do not come with VBScript support).

Adversaries may use VB payloads to execute malicious commands. Common malicious usage includes automating execution of behaviors with VBScript or embedding VBA content into Spearphishing Attachment payloads (which may also involve Mark-of-the-Web Bypass to enable execution).

Detection rules31

Rules on DetectionCode tagged with T1059.005.

Sigma24

RuleLevelLog source
Adwind RAT / JRAT File Artifacthighwindows / file_event
Csc.EXE Execution Form Potentially Suspicious Parenthighwindows / process_creation
Cscript/Wscript Uncommon Script Extension Executionhighwindows / process_creation
HackTool - CACTUSTORCH Remote Thread Creationhighwindows / create_remote_thread
HackTool - Koadic Executionhighwindows / process_creation
HackTool - NetExec File Indicatorshighwindows / file_event
HTML Help HH.EXE Suspicious Child Processhighwindows / process_creation
Potential Remote SquiblyTwo Technique Executionhighwindows / process_creation
Suspicious Child Process Of BgInfo.EXEhighwindows / process_creation
Suspicious HH.EXE Executionhighwindows / process_creation
Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBShighwindows / process_creation
Suspicious Scripting in a WMI Consumerhighwindows / wmi_event
Windows Shell/Scripting Processes Spawning Suspicious Programshighwindows / process_creation
WScript or CScript Dropper - Filehighwindows / file_event
AppLocker Application Would Have Been Blockedmediumwindows / NULL

Splunk7

RuleTypeRiskData source
Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLIAnomalyNULLCisco Network Visibility Module Flow Data
Cisco NVM - Susp Script From Archive Triggering Network ActivityAnomalyNULLCisco Network Visibility Module Flow Data
Execute Javascript With Jscript COM CLSIDTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious Process DNS Query Known Abuse Web ServicesTTPNULLSysmon EventID 22
Suspicious Process With Discord DNS QueryAnomalyNULLSysmon EventID 22
Vbscript Execution Using Wscript AppTTPNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Windows Outlook Macro Created by Suspicious ProcessTTPNULLSysmon EventID 11

Groups46

Show 22 more

Software69

Show 45 more

Campaigns16

Procedure examples131

Groups46

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening.

GroupAPT32

APT32 has used macros, COM scriptlets, and VBS scripts.

GroupAPT33

APT33 has used VBScript to initiate the delivery of payloads.

GroupAPT37

APT37 executes shellcode and a VBA script to decode Base64 strings.

GroupAPT38

APT38 has used VBScript to execute commands and other operational tasks.

GroupAPT39

APT39 has utilized malicious VBS scripts in malware.

GroupAPT42

APT42 has used a VBScript to query anti-virus products.

GroupBRONZE BUTLER

BRONZE BUTLER has used VBS and VBE scripts for execution.

View all 46 groups examples

Software69

Used byProcedure example
MalwareAstaroth

Astaroth has used malicious VBS e-mail attachments for execution.

MalwareBabyShark

BabyShark can execute additional VisualBasic content.

MalwareBackConfig

BackConfig has used VBS to install its downloader component and malicious documents with VBA macro code.

MalwareBandook

Bandook has used malicious VBA code against the target system.

MalwareBisonal

Bisonal's dropper creates VBS scripts on the victim’s machine.

MalwareBumblebee

Bumblebee can create a Visual Basic script to enable persistence.

MalwareChaes

Chaes has used VBscript to execute malicious code.

MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts.

View all 69 software examples

Campaigns16

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a VBA script called `vba_macro.exe`. This macro dropped `FONTCACHE.DAT`, the primary BlackEnergy implant; `rundll32.exe`, for executing the malware; `NTUSER.log`, an empty file; and desktop.ini, the default file used to determine folder displays on Windows machines.

Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server.

CampaignC0011

For C0011, Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host.

CampaignC0015

During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code.

CampaignFrankenstein

During Frankenstein, the threat actors used Word documents that prompted the victim to enable macros and run a Visual Basic script.

CampaignFunnyDream

During FunnyDream, the threat actors used a Visual Basic script to run remote commands.

CampaignJuicy Mix

During Juicy Mix, OilRig used VBS droppers to deliver and establish persistence for the Mango backdoor.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution.

View all 16 campaigns examples

References6

  1. Default VBS macros Blocking Open source
    Kellie Eickmeyer. (2022, February 7). Helping users stay safe: Blocking internet macros by default in Office. Retrieved February 7, 2022.
  2. Microsoft VBA Open source
    Microsoft. (2019, June 11). Office VBA Reference. Retrieved June 23, 2020.
  3. Microsoft VBScript Open source
    Microsoft. (2011, April 19). What Is VBScript?. Retrieved March 28, 2020.
  4. VB .NET Mar 2020 Open source
    .NET Team. (2020, March 11). Visual Basic support planned for .NET 5.0. Retrieved June 23, 2020.
  5. VB Microsoft Open source
    Microsoft. (n.d.). Visual Basic documentation. Retrieved June 23, 2020.
  6. Wikipedia VBA Open source
    Wikipedia. (n.d.). Visual Basic for Applications. Retrieved August 13, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.