Suspicious mshta.exe Executing Remote Media-Extension URL

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects mshta.exe invoked against a resource with a media file extension such as mp3 mp4 or png that actually hosts embedded HTA script. This proxy-execution trick is used by Lumma Stealer fake CAPTCHA campaigns to disguise the payload behind a benign-looking media URL. Detecting the mismatched extension exposes the living-off-the-land download and execution.

Related detections9 linkedT1218.005 — drag to rearrange
Malicious Mshta Spawned by WMI or WinRM Provider via process_creation
Suspicious mshta.exe Executing Embedded JavaScript from LNK Chain (via process_creation)
Suspicious VBScript Code Stored in CurrentVersion Registry Value
Suspicious rundll32 or mshta Proxy Execution of VBScript
Suspicious mshta Execution of Remote or Inline Payload (via process_creation)
Suspicious mshta Execution Proxied Through pcalua LOLBIN
Suspicious mshta Downloading Remote Payload via ClickFix
Malicious mshta Spawning PowerShell Loader via ClickFix
Suspicious Remote HTA Execution via mshta over HTTP
Suspicious mshta.exe Executing Remote Media-Extension URL
Pivot detection · T1218.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.