This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Remote CHM File Download/Execution Via HH.EXE
Original Source:
[Sigma source]
Title:
Remote CHM File Download/Execution Via HH.EXE
Status:
test
Description:
Detects the usage of "hh.exe" to execute/download remotely hosted ".chm" files.
References:
-https://www.splunk.com/en_us/blog/security/follina-for-protocol-handlers.html
-https://github.com/redcanaryco/atomic-red-team/blob/1cf4dd51f83dcb0ebe6ade902d6157ad2dbc6ac8/atomics/T1218.001/T1218.001.md
-https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-09-29
modified:
2024-01-31
Tags:
-'attack.stealth'
-'attack.t1218.001'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
OriginalFileName
:
'HH.exe'
Image|endswith
:
'\hh.exe'
selection_cli:
CommandLine|contains
:
-'http://'
-'https://'
-'\\\\'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
high