Potential LethalHTA Technique Execution

 Original Source: [Sigma source]
Title: Potential LethalHTA Technique Execution
Status: test
Description:Detects potential LethalHTA technique where the "mshta.exe" is spawned by an "svchost.exe" process
References:
  -https://codewhitesec.blogspot.com/2018/07/lethalhta.html
Author: Markus Neis
Date: 2018-06-07
modified:2023-02-07
Tags:
  • -'attack.stealth'
  • -'attack.t1218.005'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\svchost.exe'
    Image|endswith: '\mshta.exe'
  condition:selection
Falsepositives:
  -Unknown
Level: high