Class: Trojan-Clicker
Programs classified as Trojan-Clicker are designed to access Internet resources (usually web pages). This is done either by sending appropriate commands to the browser or by replacing system files that provide “standard” addresses for Internet resources (such as the Windows hosts file). A malicious user may use Trojan-Clicker programs to: increase the number of visits to certain sites in order to boost the number of hits for online ads conduct a DoS (Denial of Service) attack on a particular server lead potential victims to viruses or Trojans.Read more
Platform: HTML
Hypertext Markup Language (HTML) is the standard markup language for documents interpreted by web browsers. Markup of most web pages and web applications is written in HTML or XHTML.Family: Trojan-Clicker.HTML.Iframe
No family descriptionExamples
8D21B7A79FF514DDF2D02CC86EE7E92F00A2A8B097A41DCD3DF8CC46F5AE3DA3
F4212385A5BFBF4021865B4C81229BD3
2C48959309128A43E570DC206106639A
4BB980F62E71B3A1508CB6BFA92729FA
Tactics and Techniques: Mitre*
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use the information from System Information Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use the information from System Information Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.