T1218.005 Mshta in real malware
ATT&CK technique T1218.005 Mshta appears in 17 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is rising (8 recent vs 0 prior). Most associated families: Acsogenixx, Cerber, GenBadur, NMVT.
Tactics: stealth
Prevalence in the corpus
- Samples exhibiting T1218.005: 17
- Share of analyzed corpus: 0.0%
- Last 7 days: 8 · prior 7 days: 0 (rising)
Malware families using T1218.005
- Acsogenixx - 1 sample
- Cerber - 1 sample
- GenBadur - 1 sample
- NMVT - 1 sample
Example samples
- b21f723cbd13e22da1540d4dd598c33b8445fca980f615a236a3b9fc411fe3b1 - malicious
- 4ba458e551eb2d9e6ec8d44274994eb1b1851a5f17e99ef712103953b15eeb69 - suspicious
- f278c82aba15b05cfb901dd3f2b0fed5425b09ead9d2c3a8500052de366a3df3.hta - suspicious
- nfe_doc-VXNTFD.hta - suspicious
- 02c1cfc5a95100ed96175d895823c581835971cb24aceb13c17129f6f55ca70f.hta - suspicious
- 02fdd673a10bf5e1acf1ec10c54d4df40822a189f9a50e27c5f10d563eab05eb.hta - suspicious
- DOC-O8MS70.lnk - suspicious
- Contrato_Indeniza_Brasil-UJ1CH6.lnk - malicious
- 4b8ef3c6a07059e723e7f49415aedadebc84ccd8d5490d071252117fb19031f4 - suspicious
- silverfox_hta.hta - malicious
- 1dba7ae6ba0a2814d90744f4596bee18dec44141498a5ca978230e8bc53a4459.hta - malicious
- 0585547fd8fb93a98ff616249edfa78f28e2d0a57c56a8453d39c418935bf79a.lnk - malicious
- 2210b14d4791b4edfdb8cedb71482bfb0ecc21cf9d42793f9d06e522eba50430.hta - malicious
- Confirmacion_de_Pago_Pendiente.pdf.hta - malicious
- HTML.NoMercy.b.html - malicious
- cerber.exe - malicious
- ed48e74129c7f946abf72f6a14d4683a69cad54787e91c8a0b84b41b5eedfbd5.hta - malicious
Canonical technique definition: MITRE ATT&CK T1218.005 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1218.005
- How common is ATT&CK T1218.005 (Mshta) in real malware?
- ATT&CK technique T1218.005 Mshta appears in 17 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is rising (8 recent vs 0 prior). Most associated families: Acsogenixx, Cerber, GenBadur, NMVT.
- Is T1218.005 becoming more common?
- Prevalence is rising: 8 samples in the last seven days against 0 in the seven days before. This measures submissions to MalwareAnalyzer by Cyble, so it reflects what is being submitted here rather than global attacker behaviour.
- Which malware families use T1218.005?
- In this corpus T1218.005 is most associated with Acsogenixx (1), Cerber (1), GenBadur (1), NMVT (1). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1218.005?
- 0.0% of the publicly analyzed corpus (17 of 100981 samples) exhibits T1218.005. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats