Analytics BIOC Low

Mshta.exe spawns from a browser process

Mshta is the Microsoft HTML Application Host. It executes HTML applications on Windows. Detected when a browser process has spawned mshta, which can be a potential attack vector.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Mshta (T1218.005)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:

Execute malicious code through system binary proxy execution to bypass application controls and security monitoring.

Investigative actions:

Examine the command line arguments passed to mshta for suspicious URLs or file paths. Check the browser process that spawned mshta for signs of compromise. Review network connections around the time of execution. Analyze any HTML applications (.hta files) that may have been executed.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Mshta.exe spawns from a browser process that executes a script from a URL Medium (parent: Low)