Class: Trojan
A malicious program designed to electronically spy on the user’s activities (intercept keyboard input, take screenshots, capture a list of active applications, etc.). The collected information is sent to the cybercriminal by various means, including email, FTP, and HTTP (by sending data in a request).Read more
Platform: Win32
Win32 is an API on Windows NT-based operating systems (Windows XP, Windows 7, etc.) that supports execution of 32-bit applications. One of the most widespread programming platforms in the world.Family: Trojan.Multi.Runner
No family descriptionExamples
BE255BC92AF3EABC7DAE537747AF92B0E92608006FEE4F3012DBE89B812CD270
42AEE355E8791E7FFF0A8CCB6BE1C945
3F1E868460A2E3201EEB89EAEEB92FCC
CA13050EAE5E4783CE497E8115CBD04A
Tactics and Techniques: Mitre*
TA0005
Defense Evasion
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code
T1218.005
Mshta
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code
* © 2025 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.