Suspicious MSHTA Child Process

 Original Source: [Sigma source]
Title: Suspicious MSHTA Child Process
Status: test
Description:Detects a suspicious process spawning from an "mshta.exe" process, which could be indicative of a malicious HTA script execution
References:
  -https://www.trustedsec.com/july-2015/malicious-htas/
Author: Michael Haag
Date: 2019-01-16
modified:2023-02-06
Tags:
  • -'attack.stealth'
  • -'attack.t1218.005'
  • -'car.2013-02-003'
  • -'car.2013-03-001'
  • -'car.2014-04-003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent:
    ParentImage|endswith: '\mshta.exe'
  selection_child:
    - Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\sh.exe'
      - '\bash.exe'
      - '\reg.exe'
      - '\regsvr32.exe'
      - '\bitsadmin.exe'
    - OriginalFileName:
      - 'Cmd.Exe'
      - 'PowerShell.EXE'
      - 'pwsh.dll'
      - 'wscript.exe'
      - 'cscript.exe'
      - 'Bash.exe'
      - 'reg.exe'
      - 'REGSVR32.EXE'
      - 'bitsadmin.exe'
  condition:all of selection*
Falsepositives:
  -Printer software / driver installations
  -HP software
Level: high