T1218.005Mshta
T1218.005 — Mshta is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 17 detection use cases covering it and 4 threat-intel articles citing it.
Defense Evasion
17Use cases
4Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1218 · System Binary Proxy Execution
Use cases covering this technique (17)
[WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download Detect mshta inline hta execution Detect mshta renamed Detect MSHTA Url in Command Line Detect Rundll32 Inline HTA Execution Mshta spawning Rundll32 OR Regsvr32 Process Suspicious mshta child process Suspicious mshta spawn Windows Mshta Execution In Registry Windows MSHTA Writing to World Writable Path Windows Process Writing File to World Writable Path [LLM] MSHTA remote HTA launched by explorer→powershell chain (ACR Stealer fileless campaign) [LLM] ClickFix mshta.exe silently executing remote HTA then dropping batch (UAT-11795 initial access) [LLM] mshta.exe HTA downloader reaching UAT-11795 staging domains (ClickFix) [LLM] Gamaredon HTA downloader auto-executing from Startup folder at logon (mshta.exe)Articles citing this technique (4)
crit Begun, the Patch Wars have art-150