Class: Trojan
A malicious program designed to electronically spy on the user’s activities (intercept keyboard input, take screenshots, capture a list of active applications, etc.). The collected information is sent to the cybercriminal by various means, including email, FTP, and HTTP (by sending data in a request).Read more
Platform: Win32
Win32 is an API on Windows NT-based operating systems (Windows XP, Windows 7, etc.) that supports execution of 32-bit applications. One of the most widespread programming platforms in the world.Family: Trojan.Multi.Runner
No family descriptionExamples
78717CC95AEDE35F12CD83DBBB4D6D428F87A964C17A1A3490C822BE57664285
2E723A361A9D34526FE2D6CA83488C52
7EB299C2C80F61ABC91FDE48A01083D5
5855A95127EE830979695952F787A97D
Tactics and Techniques: Mitre*
TA0005
Defense Evasion
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code
T1218.005
Mshta
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code
* © 2025 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.