Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org
Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as Component Object Model and the Native API through the Windows API. Although tagged as legacy with no planned future evolutions, VB is integrated and supported in the .NET Framework and cross-platform .NET Core.
Derivative languages based on VB have also been created, such as Visual Basic for Applications (VBA) and VBScript. VBA is an event-driven programming language built into Microsoft Office, as well as several third-party applications. VBA enables documents to contain macros used to automate the execution of tasks and other functionality on the host. VBScript is a default scripting language on Windows hosts and can also be used in place of JavaScript on HTML Application (HTA) webpages served to Internet Explorer (though most modern browsers do not come with VBScript support).
Adversaries may use VB payloads to execute malicious commands. Common malicious usage includes automating execution of behaviors with VBScript or embedding VBA content into Spearphishing Attachment payloads (which may also involve Mark-of-the-Web Bypass to enable execution).
Rules on DetectionCode tagged with T1059.005.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI | Anomaly | NULL | Cisco Network Visibility Module Flow Data |
| Cisco NVM - Susp Script From Archive Triggering Network Activity | Anomaly | NULL | Cisco Network Visibility Module Flow Data |
| Execute Javascript With Jscript COM CLSID | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious Process DNS Query Known Abuse Web Services | TTP | NULL | Sysmon EventID 22 |
| Suspicious Process With Discord DNS Query | Anomaly | NULL | Sysmon EventID 22 |
| Vbscript Execution Using Wscript App | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Outlook Macro Created by Suspicious Process | TTP | NULL | Sysmon EventID 11 |
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening. |
| GroupAPT32 | APT32 has used macros, COM scriptlets, and VBS scripts. |
| GroupAPT33 | APT33 has used VBScript to initiate the delivery of payloads. |
| GroupAPT37 | APT37 executes shellcode and a VBA script to decode Base64 strings. |
| GroupAPT38 | APT38 has used VBScript to execute commands and other operational tasks. |
| GroupAPT39 | APT39 has utilized malicious VBS scripts in malware. |
| GroupAPT42 | APT42 has used a VBScript to query anti-virus products. |
| GroupBRONZE BUTLER | BRONZE BUTLER has used VBS and VBE scripts for execution. |
| Used by | Procedure example |
|---|---|
| MalwareAstaroth | Astaroth has used malicious VBS e-mail attachments for execution. |
| MalwareBabyShark | BabyShark can execute additional VisualBasic content. |
| MalwareBackConfig | BackConfig has used VBS to install its downloader component and malicious documents with VBA macro code. |
| MalwareBandook | Bandook has used malicious VBA code against the target system. |
| MalwareBisonal | Bisonal's dropper creates VBS scripts on the victim’s machine. |
| MalwareBumblebee | Bumblebee can create a Visual Basic script to enable persistence. |
| MalwareChaes | Chaes has used VBscript to execute malicious code. |
| MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts. |
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a VBA script called `vba_macro.exe`. This macro dropped `FONTCACHE.DAT`, the primary BlackEnergy implant; `rundll32.exe`, for executing the malware; `NTUSER.log`, an empty file; and desktop.ini, the default file used to determine folder displays on Windows machines. |
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server. |
| CampaignC0011 | For C0011, Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host. |
| CampaignC0015 | During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code. |
| CampaignFrankenstein | During Frankenstein, the threat actors used Word documents that prompted the victim to enable macros and run a Visual Basic script. |
| CampaignFunnyDream | During FunnyDream, the threat actors used a Visual Basic script to run remote commands. |
| CampaignJuicy Mix | During Juicy Mix, OilRig used VBS droppers to deliver and establish persistence for the Mango backdoor. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.