MB-aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15
high
📛 Threat Title
Unknown: dekont.hta
Description
File type: hta. Size: 2314675 bytes. Tags: hta. Reporter: lowmal3. First seen: 2026-05-15 10:45:32.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
dekont.hta
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dekont.hta
IOC database
- Type
- domain
- Value
dekont.hta- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dekont.hta
hash_sha1
d8e652207d6cea3c37ec85d982c07bcb384f0d03
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d8e652207d6cea3c37ec85d982c07bcb384f0d03
1 feed
IOC database
- Type
- hash_sha1
- Value
d8e652207d6cea3c37ec85d982c07bcb384f0d03- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Imported from threat-intel feed: Abuse.ch
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d8e652207d6cea3c37ec85d982c07bcb384f0d03
hash_sha256
aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15
1 feed
IOC database
- Type
- hash_sha256
- Value
aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15
hash_md5
02e6dbd3f245338ca17bea63eca7a996
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/02e6dbd3f245338ca17bea63eca7a996
1 feed
IOC database
- Type
- hash_md5
- Value
02e6dbd3f245338ca17bea63eca7a996- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/02e6dbd3f245338ca17bea63eca7a996
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: unknown. Size: 2314675 bytes. Reporter: lowmal3. First seen: 2026-05-15 10:45:32.
Remediations (10)
-
web:attack.mitre.org
Other sub-techniques of System Binary Proxy Execution (14) Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code [1] [2] [3] [4] [5]
-
web:docs.lenovocdrt.com
This solution replaces the older Think BIOS Config Tool which was implemented as an HTA. Archived documentation for the HTA version is still available here: Think BIOS Config Tool - HTA Previously created INI files from the HTA version which contain an encrypted password are not compatible with the new Think BIOS Config Tool V2 due to changes in encryption methods. Please recreate the INI ...
-
web:github.com
An HTA is a proprietary Windows program whose source code consists of HTML and one or more scripting languages supported by Internet Explorer (VBScript and JScript). An HTA is executed using mshta.exe, which is typically installed along with IE. In fact, mshta is dependant on IE, so if it has been uninstalled, HTAs will be unable to execute.We can create a malicious hta file and use it on ...
-
web:knowledge.broadcom.com
HTAware Mitigation Remediation Usage: Retrieve HTAware Mitigation configuration The current HTAware Mitigation configuration can be retrieved by specifying either a vSphere Cluster or an individual ESXi host.
-
web:support.microsoft.com
The detection script collects Secure Boot and certificate status from each device and reports it back to the Intune portal — no remediation action is taken on devices. This gives administrators a centralized, exportable view of certificate update progress across their Intune enrolled Windows devices. Why use this approach?
-
web:www.huntress.com
CVE-2017-0199 exploits how Microsoft Office applications handle HTA (HTML Application) files embedded within OLE objects. Attackers craft a seemingly legitimate document that, upon opening, retrieves an external HTA file containing malicious scripts. This file is then executed without the user's consent, allowing the attacker to gain control over the system. The vulnerability stems from the ...
-
web:www.ispor.org
This systematic literature review (SLR) assessed how heath technology assessment (HTA) bodies have evaluated and critiqued mitigation approaches to address treatment switching impacting OS, and acceptance of unaffected endpoints [e.g. progression-free survival (PFS)] in clinical trials studying advanced/metastatic cancer of lung (non-small cell ...
-
web:www.joesandbox.com
Behavior Graph ID: 1914074 Sample: dekont.hta Startdate: 15/05/2026 Architecture: WINDOWS Score: 84 updatedserver.shop Malicious sample detected (through community Yara rule) Yara detected Powershell download and execute Sigma detected: Suspicious MSHTA Child Process Joe Sandbox ML detected suspicious sample mshta.exe 1 started Suspicious ...
-
web:www.reddit.com
If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...
-
web:www.varonis.com
All too often, .hta is still associated with mshta. #humans! In other words, by clicking on a file with an .hta suffix, the victim of a phishing email launches mshta and runs the script embedded in the HTML.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.