Malicious Equation Editor Child Process Execution via process_creation

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-05-03
Updated
2026-08-28

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects the Microsoft Equation Editor EQNEDT32.EXE spawning any child process which almost always indicates exploitation of the CVE-2017-11882 memory corruption vulnerability. SideWinder delivered RTF documents that exploited Equation Editor to launch mshta.exe and fetch a remote HTA payload against maritime and nuclear targets. Equation Editor never legitimately creates child processes so this is a high confidence exploitation signal.

Related detections9 linkedT1566.001 — drag to rearrange
Malicious Microsoft Word Spawning Anomalous Child Process via CVE-2023-36884 (via process_creation)
Windows Security Event 5379: Opened Password-Protected ZIP from Outlook Attachment
Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Malicious Non-Interactive Encoded PowerShell Stager (via process_creation)
Suspicious Hidden PowerShell Executing Substring of Dropped File
PowerShell Encoded or Download-Cradle Command Line (via process_creation)
Malicious Equation Editor Child Process Execution via process_creation
Pivot detection · T1566.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.