Suspicious Fake Sohu Updater Execution

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects execution of an executable whose name contains sohuva_update which impersonates a Sohu software updater. Evasive Panda delivered a fake updater with this naming pattern via DNS poisoning to drop MgBot as reported by Kaspersky. Execution of this masquerading updater indicates drive by compromise and initial payload execution.

Related detections7 linkedT1189 — drag to rearrange
Suspicious Connection to Local Zoom Opener Webserver Launch Endpoint (via network_connection)
Suspicious macOS Installer Invocation Spawned via Zoom Opener Helper (via process_creation)
Suspicious FakeBat Fake Browser Update Stats and Download Endpoints (via proxy)
Suspicious Watering Hole Exfiltration to Fake wp-includes Endpoint via SilentSelfie
Suspicious Child Processes Spawned by Browsers on macOS
Webserver GET requests containing XSS-related payload strings
Proxy Web Requests for Flash Player Installer from Unofficial Locations
Suspicious Fake Sohu Updater Execution
Pivot detection · T1189 · 7 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.