BIOC Informational

Browser downloads an .hta or .application file

.hta and .application files are Windows applications that may serve as an attack vector by executing code maliciously using trusted Windows applications.

Module:
Platform Analytics
Agent event type:
File
Category:
Execution
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Mshta (T1218.005)
Indicator:

File action type = create , write AND file name = *.hta , *.application Process initiated by = iexplore.exe , chrome.exe , firefox.exe , opera.exe , microsoftedge.exe , microsoftedgecp.exe , safari.exe , cgo name = iexplore.exe , chrome.exe , firefox.exe , opera.exe , microsoftedge.exe , microsoftedgecp.exe , safari.exe

Preventable: yes