Malicious Microsoft Word Spawning Anomalous Child Process via CVE-2023-36884 (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-06-02
Updated
2026-08-28

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects winword.exe spawning mshta.exe, splwow64.exe, powershell.exe or cmd.exe, the exploitation chain of CVE-2023-36884 by Storm-0978. A weaponized document triggers these anomalous child processes to fetch and run a RomCom-like backdoor after the victim opens the lure.

Related detections9 linkedT1203 — drag to rearrange
Malicious Equation Editor Child Process Execution via process_creation
Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Suspicious mstsc Launch of RDP File From User Download or Temp Path (via process_creation)
Suspicious Regsvr32 Squiblydoo Remote Scriptlet Execution via Command Line (via process_creation)
Malicious Script Execution from WinRAR Extraction Directory via CVE-2023-38831
Suspicious Execution From WinRAR Temporary Extraction Path via Command Line (via process_creation)
Malicious Microsoft Word Spawning Anomalous Child Process via CVE-2023-36884 (via process_creation)
Pivot detection · T1203 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.