Sub-technique of T1204 User Execution.View on attack.mitre.org
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Adversaries may employ various forms of Masquerading and Obfuscated Files or Information to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it.
While Malicious File frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing.
Rules on DetectionCode tagged with T1204.002.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Batch File Write to System32 | Anomaly | NULL | Sysmon EventID 11 |
| Cisco NVM - Susp Script From Archive Triggering Network Activity | Anomaly | NULL | Cisco Network Visibility Module Flow Data |
| Drop IcedID License dat | Hunting | NULL | Sysmon EventID 11 |
| Linux Ghostscript Exploitation | TTP | NULL | Sysmon for Linux EventID 1 |
| O365 SharePoint Malware Detection | TTP | NULL | Office 365 Universal Audit Log |
| O365 Threat Intelligence Suspicious File Detected | TTP | NULL | Office 365 Universal Audit Log |
| Single Letter Process On Endpoint | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious Process Executed From Container File | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Uncommon Processes On Endpoint | Hunting | NULL | Sysmon EventID 1 |
| Windows Advanced Installer MSIX with AI_STUBS Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows AppX Deployment Full Trust Package Installation | Hunting | NULL | Windows Event Log AppXDeployment-Server 400 |
| Windows AppX Deployment Package Installation Success | Anomaly | NULL | Windows Event Log AppXDeployment-Server 854 |
| Windows AppX Deployment Unsigned Package Installation | TTP | NULL | Windows Event Log AppXDeployment-Server 855 |
| Windows Binary Execution from an Archive | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Default Cobalt Strike PowerShell Beacon | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Developer-Signed MSIX Package Installation | Anomaly | NULL | Windows Event Log AppXDeployment-Server 855 |
| Windows EFI Volume Mount Attempt Via Mountvol | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Explorer LNK Exploit Process Launch With Padding | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Windows Explorer.exe Spawning PowerShell or Cmd | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Windows MSIX Package Interaction | Hunting | NULL | Windows Event Log AppXPackaging 171 |
| Windows Mustang Panda USB Tool Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows NorthStar C2 Agent Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows PowerShell Script From WindowsApps Directory | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Suspect Process With Authentication Traffic | Anomaly | NULL | Sysmon EventID 3 |
| Windows Suspicious QEMU Execution | TTP | NULL | Sysmon EventID 1 |
| Windows Universal Data Link File Creation | Anomaly | NULL | Sysmon EventID 11 |
| Windows User Execution Malicious URL Shortcut File | Anomaly | NULL | Sysmon EventID 11 |
| Used by | Procedure example |
|---|---|
| Groupadmin@338 | admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails. |
| GroupAjax Security Team | Ajax Security Team has lured victims into executing malicious files. |
| GroupAndariel | Andariel has attempted to lure victims into enabling malicious macros within email attachments. |
| GroupAoqin Dragon | Aoqin Dragon has lured victims into opening weaponized documents, fake external drives, and fake antivirus to execute malicious payloads. |
| GroupAPT-C-36 | APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware. |
| GroupAPT12 | APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing. |
| GroupAPT19 | APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails. |
| GroupAPT28 | APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts. |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla has been executed through malicious e-mail attachments |
| MalwareAppleJeus | AppleJeus has required user execution of a malicious MSI installer. |
| MalwareAppleSeed | AppleSeed can achieve execution through users running malicious file attachments distributed via email. |
| MalwareAshTag | AshTag has been executed through victims downloading and opening malicious RAR archive files. |
| MalwareAstaroth | Astaroth has used malicious files including VBS, LNK, and HTML for execution. |
| ToolAsyncRAT | AsyncRAT has been executed through victims opening malicious file attachments. |
| MalwareBad Rabbit | Bad Rabbit has been executed through user installation of an executable disguised as a flash installer. |
| MalwareBADFLICK | BADFLICK has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them. |
| CampaignC0011 | During C0011, Transparent Tribe relied on a student target to open a malicious document delivered via email. |
| CampaignC0015 | During C0015, the threat actors relied on users to enable macros within a malicious Microsoft Word document. |
| CampaignFrankenstein | During Frankenstein, the threat actors relied on a victim to enable macros within a malicious Microsoft Word document likely sent via email. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace lured victims into executing malicious payloads by opening email attachments. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors. |
| CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors relied on potential victims to open a malicious Microsoft Word document sent via email. |
| CampaignOperation Honeybee | During Operation Honeybee, threat actors relied on a victim to enable macros within a malicious Word document. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.