s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15 high

📛 Threat Title

Unknown: dekont.hta

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: hta. Size: 2314675 bytes. Tags: hta. Reporter: lowmal3. First seen: 2026-05-15 10:45:32.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain dekont.hta VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dekont.hta

IOC database

Type
domain
Value
dekont.hta
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dekont.hta

hash_sha1 d8e652207d6cea3c37ec85d982c07bcb384f0d03 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d8e652207d6cea3c37ec85d982c07bcb384f0d03
1 feed

IOC database

Type
hash_sha1
Value
d8e652207d6cea3c37ec85d982c07bcb384f0d03
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Imported from threat-intel feed: Abuse.ch

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d8e652207d6cea3c37ec85d982c07bcb384f0d03

hash_sha256 aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15
1 feed

IOC database

Type
hash_sha256
Value
aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/aa37a0f7540b0b5b983b2bc51448c9e39e7d3aba82dac5396e4eae0c3e649f15

hash_md5 02e6dbd3f245338ca17bea63eca7a996 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/02e6dbd3f245338ca17bea63eca7a996
1 feed

IOC database

Type
hash_md5
Value
02e6dbd3f245338ca17bea63eca7a996
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/02e6dbd3f245338ca17bea63eca7a996

References (1)

Remediations (10)

  • web:attack.mitre.org

    Other sub-techniques of System Binary Proxy Execution (14) Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code [1] [2] [3] [4] [5]

  • web:docs.lenovocdrt.com

    This solution replaces the older Think BIOS Config Tool which was implemented as an HTA. Archived documentation for the HTA version is still available here: Think BIOS Config Tool - HTA Previously created INI files from the HTA version which contain an encrypted password are not compatible with the new Think BIOS Config Tool V2 due to changes in encryption methods. Please recreate the INI ...

  • web:github.com

    An HTA is a proprietary Windows program whose source code consists of HTML and one or more scripting languages supported by Internet Explorer (VBScript and JScript). An HTA is executed using mshta.exe, which is typically installed along with IE. In fact, mshta is dependant on IE, so if it has been uninstalled, HTAs will be unable to execute.We can create a malicious hta file and use it on ...

  • web:knowledge.broadcom.com

    HTAware Mitigation Remediation Usage: Retrieve HTAware Mitigation configuration The current HTAware Mitigation configuration can be retrieved by specifying either a vSphere Cluster or an individual ESXi host.

  • web:support.microsoft.com

    The detection script collects Secure Boot and certificate status from each device and reports it back to the Intune portal — no remediation action is taken on devices. This gives administrators a centralized, exportable view of certificate update progress across their Intune enrolled Windows devices. Why use this approach?

  • web:www.huntress.com

    CVE-2017-0199 exploits how Microsoft Office applications handle HTA (HTML Application) files embedded within OLE objects. Attackers craft a seemingly legitimate document that, upon opening, retrieves an external HTA file containing malicious scripts. This file is then executed without the user's consent, allowing the attacker to gain control over the system. The vulnerability stems from the ...

  • web:www.ispor.org

    This systematic literature review (SLR) assessed how heath technology assessment (HTA) bodies have evaluated and critiqued mitigation approaches to address treatment switching impacting OS, and acceptance of unaffected endpoints [e.g. progression-free survival (PFS)] in clinical trials studying advanced/metastatic cancer of lung (non-small cell ...

  • web:www.joesandbox.com

    Behavior Graph ID: 1914074 Sample: dekont.hta Startdate: 15/05/2026 Architecture: WINDOWS Score: 84 updatedserver.shop Malicious sample detected (through community Yara rule) Yara detected Powershell download and execute Sigma detected: Suspicious MSHTA Child Process Joe Sandbox ML detected suspicious sample mshta.exe 1 started Suspicious ...

  • web:www.reddit.com

    If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...

  • web:www.varonis.com

    All too often, .hta is still associated with mshta. #humans! In other words, by clicking on a file with an .hta suffix, the victim of a phishing email launches mshta and runs the script embedded in the HTML.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.