Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0342 — Detection of Suspicious Compiled HTML File Execution via hh.exe
DET0342

Detection of Suspicious Compiled HTML File Execution via hh.exe

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0968 Analytic 0968
Windows

Execution of hh.exe to open a .chm file followed by suspicious child processes or script engine invocation (VBScript, JScript, mshta, powershell). Behavior includes loading a CHM file from untrusted locations, or immediately spawning commands indicative of payload execution.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=3, 22
[CHMPathRegex] Regex matching CHM file locations; tune to exclude trusted internal software help files
[ChildProcessList] List of suspicious children of hh.exe (powershell.exe, cmd.exe, mshta.exe, wscript.exe)
[NetworkDestinationAllowlist] Filter for legitimate update/help servers accessed by hh.exe
[TimeWindow] Threshold time between hh.exe execution and suspicious follow-on activity

Detected Techniques

1

Details

MITRE ID
DET0342
STIX ID
x-mitre-detection-strategy--fafb9522-c185-48e0-b0a5-e65887f5deb4
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.