This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HH.EXE Execution
Original Source:
[Sigma source]
Title:
HH.EXE Execution
Status:
test
Description:
Detects the execution of "hh.exe" to open ".chm" files.
References:
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1218.001/T1218.001.md
-https://eqllib.readthedocs.io/en/latest/analytics/b25aa548-7937-11e9-8f5c-d46d6d62a49e.html
-https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37
Author:
E.M. Anhaus (originally from Atomic Blue Detections, Dan Beavin), oscd.community
Date:
2019-10-24
modified:
2023-12-11
Tags:
-'attack.stealth'
-'attack.t1218.001'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
OriginalFileName
:
'HH.exe'
Image|endswith
:
'\hh.exe'
selection_cli:
CommandLine|contains
:
'.chm'
condition
:
all of selection_*
Falsepositives:
-False positives are expected with legitimate ".CHM"
Level:
low