{"id":"T1218.005","name":"Mshta","url":"https://attack.mitre.org/techniques/T1218/005","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0506","stix_id":"x-mitre-detection-strategy--8d06728f-5b50-4925-a05c-4d56b17ba5d2","name":"Detecting Mshta-based Proxy Execution via Suspicious HTA or Script Invocation","url":"https://attack.mitre.org/detectionstrategies/DET0506","analytics":[{"id":"AN1397","stix_id":"x-mitre-analytic--e6037bea-ba25-40bf-b681-361d4f901adb","name":"Analytic 1397","description":"Detection of mshta.exe execution where command-line arguments reference remote or local HTA/script content (VBScript/JScript) followed by subsequent file creation, network retrieval, or process spawning that indicates payload execution outside standard Internet Explorer security context. Correlation includes parent process lineage, command-line inspection, and network connection creation to untrusted or anomalous endpoints.","url":"https://attack.mitre.org/detectionstrategies/DET0506#AN1397","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"CommandLinePattern","description":"Regex patterns for mshta.exe arguments referencing remote HTA/script content; may need tuning to exclude known-good internal scripts."},{"field":"SuspiciousParentProcesses","description":"List of parent processes considered suspicious when spawning mshta.exe (e.g., Office applications, script interpreters)."},{"field":"AllowedHTASources","description":"Whitelist of domains/paths from which legitimate HTAs are executed."},{"field":"TimeWindow","description":"Time threshold for correlating mshta.exe execution with subsequent network connections or file creations."}],"live":true,"detection_strategies":["DET0506"],"techniques":["T1218.005"]}],"live":true,"version":"1.0","techniques":["T1218.005"]}],"sigma_rules":[{"id":"03cc0c25-389f-4bf8-b48d-11878079f1ca","title":"Suspicious MSHTA Child Process","author":"Michael Haag","status":"test","level":"high","date":"2019-01-16","modified":"2023-02-06","description":"Detects a suspicious process spawning from an \"mshta.exe\" process, which could be indicative of a malicious HTA script execution","references":["https://www.trustedsec.com/july-2015/malicious-htas/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.005","car.2013-02-003","car.2013-03-001","car.2014-04-003"],"path":"rules/windows/process_creation/proc_creation_win_mshta_susp_child_processes.yml","techniques":["T1218.005"],"cves":[]},{"id":"2b30fa36-3a18-402f-a22d-bf4ce2189f35","title":"Potential Baby Shark Malware Activity","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-02-24","modified":"2023-03-08","description":"Detects activity that could be related to Baby Shark malware","references":["https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.discovery","attack.stealth","attack.t1012","attack.t1059.003","attack.t1059.001","attack.t1218.005","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Malware/BabyShark/proc_creation_win_malware_babyshark.yml","techniques":["T1012","T1059.003","T1059.001","T1218.005"],"cves":[]},{"id":"2e4e488a-6164-4811-9ea1-f960c7359c40","title":"HackTool - CACTUSTORCH Remote Thread Creation","author":"@SBousseaden (detection), Thomas Patzke (rule)","status":"test","level":"high","date":"2019-02-01","modified":"2023-05-05","description":"Detects remote thread creation from CACTUSTORCH as described in references.","references":["https://twitter.com/SBousseaden/status/1090588499517079552","https://github.com/mdsecactivebreach/CACTUSTORCH"],"logsource":{"product":"windows","category":"create_remote_thread"},"tags":["attack.privilege-escalation","attack.execution","attack.stealth","attack.t1055.012","attack.t1059.005","attack.t1059.007","attack.t1218.005"],"path":"rules/windows/create_remote_thread/create_remote_thread_win_hktl_cactustorch.yml","techniques":["T1055.012","T1059.005","T1059.007","T1218.005"],"cves":[]},{"id":"67f113fa-e23d-4271-befa-30113b3e08b1","title":"Suspicious JavaScript Execution Via Mshta.EXE","author":"E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community","status":"test","level":"high","date":"2019-10-24","modified":"2023-02-07","description":"Detects execution of javascript code using \"mshta.exe\".","references":["https://eqllib.readthedocs.io/en/latest/analytics/6bc283c4-21f2-4aed-a05c-a9a3ffa95dd4.html","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1218.005/T1218.005.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.005"],"path":"rules/windows/process_creation/proc_creation_win_mshta_javascript.yml","techniques":["T1218.005"],"cves":[]},{"id":"b730a276-6b63-41b8-bcf8-55930c8fc6ee","title":"Csc.EXE Execution Form Potentially Suspicious Parent","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)","status":"test","level":"high","date":"2019-02-11","modified":"2026-03-23","description":"Detects a potentially suspicious parent of \"csc.exe\", which could be a sign of payload delivery.","references":["https://www.uptycs.com/blog/warzonerat-can-now-evade-with-process-hollowing","https://reaqta.com/2017/11/short-journey-darkvnc/","https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/yellow-liderc-ships-its-scripts-delivers-imaploader-malware.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1059.005","attack.t1059.007","attack.t1218.005","attack.t1027.004"],"path":"rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml","techniques":["T1059.005","T1059.007","T1218.005","T1027.004"],"cves":[]},{"id":"b98d0db6-511d-45de-ad02-e82a98729620","title":"Remotely Hosted HTA File Executed Via Mshta.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-08","modified":"2023-02-06","description":"Detects execution of the \"mshta\" utility with an argument containing the \"http\" keyword, which could indicate that an attacker is executing a remotely hosted malicious hta file","references":["https://www.trendmicro.com/en_us/research/22/e/avoslocker-ransomware-variant-abuses-driver-file-to-disable-anti-Virus-scans-log4shell.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1218.005"],"path":"rules/windows/process_creation/proc_creation_win_mshta_http.yml","techniques":["T1218.005"],"cves":[]},{"id":"cc7abbd0-762b-41e3-8a26-57ad50d2eea3","title":"MSHTA Execution with Suspicious File Extensions","author":"Diego Perez (@darkquassar), Markus Neis, Swisscom (Improve Rule), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"test","level":"high","date":"2019-02-22","modified":"2025-05-12","description":"Detects execution of mshta.exe with file types that looks like they do not typically represent HTA (HTML Application) content,\nsuch as .png, .jpg, .zip, .pdf, and others, which are often polyglots. MSHTA is a legitimate Windows utility for executing HTML Applications\ncontaining VBScript or JScript. Threat actors often abuse this lolbin utility to download and\nexecute malicious scripts disguised as benign files or hosted under misleading extensions to evade detection.\n","references":["http://blog.sevagas.com/?Hacking-around-HTA-files","https://0x00sec.org/t/clientside-exploitation-in-2018-how-pentesting-has-changed/7356","https://learn.microsoft.com/en-us/previous-versions/dotnet/framework/data/xml/xslt/xslt-stylesheet-scripting-using-msxsl-script","https://medium.com/tsscyber/pentesting-and-hta-bypassing-powershell-constrained-language-mode-53a42856c997","https://twitter.com/mattifestation/status/1326228491302563846","https://www.virustotal.com/gui/file/c1f27d9795a2eba630db8a043580a0761798f06370fb1317067805f8a845b00c"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1140","attack.t1218.005","attack.execution","attack.t1059.007","cve.2020-1599"],"path":"rules/windows/process_creation/proc_creation_win_mshta_susp_execution.yml","techniques":["T1140","T1218.005","T1059.007"],"cves":["CVE-2020-1599"]},{"id":"ed5d72a6-f8f4-479d-ba79-02f6a80d7471","title":"Potential LethalHTA Technique Execution","author":"Markus Neis","status":"test","level":"high","date":"2018-06-07","modified":"2023-02-07","description":"Detects potential LethalHTA technique where the \"mshta.exe\" is spawned by an \"svchost.exe\" process","references":["https://codewhitesec.blogspot.com/2018/07/lethalhta.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.005"],"path":"rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml","techniques":["T1218.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}