• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Possible mshta.exe Remote .hta Payload Download (SideCopy LNK Chain)

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ankit Mehta@Secvyn
    •updated 8 days ago•1•0•2

    Detects HTTP GET requests for files with a .hta extension, utilizing a legacy Internet Explorer User-Agent string. This pattern is commonly associated with SideCopy threat group activities where mshta.exe is used to proxy the execution of remotely hosted malicious HTA files, often as part of an initial infection chain.

    Suricata

    Tags

    T1218.005 - MshtaT1566.001 - Spearphishing AttachmentG1008 - SideCopyTA0005 - StealthNetwork Connection OutboundHTTP RequestFile DownloadIDS IPS AlertWindowsNetwork GenericSuricata IDSSnort IDSHTTPTrojan Activity

    Found in

    • SideCopy Expanding Spear-Phishing to Indian AcademiaLast updated 16 days ago
    • SideCopy Expanding Spear-Phishing to Indian AcademiaLast updated 16 days ago
    • SideCopy Expanding Spear-Phishing to Indian AcademiaLast updated 16 days ago
    • SideCopy Expanding Spear-Phishing to Indian AcademiaLast updated 16 days ago
    • SideCopy Expanding Spear-Phishing to Indian AcademiaLast updated 16 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?