Suspicious HealthApp Batch File Persistence in Start Menu Startup Folder

PremiumReviewedSigma · High · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-10-06
Updated
2026-10-06

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation of a batch file named after the HealthApp masquerade inside the Start Menu Programs startup folder. The Maverick banking Trojan established persistence by dropping a HealthApp-[GUID].bat file into the user startup location so it re-executes at logon. A batch script placed in the startup folder is a classic autostart persistence mechanism abused to survive reboots.

Related detections9 linkedT1547.001 — drag to rearrange
Suspicious Python Script Persistence in User Startup Folder
Suspicious FatalRAT Run Key Persistence to ProgramData Loader (via registry_set)
Suspicious VBScript Persistence in CurrentVersion Run Key
Malicious Sibot Malware Registry Persistence Value
Suspicious Run Key Persistence in CurrentVersion (via registry_set)
Suspicious Run Key Persistence Referencing Script Files Linked to FIN7
Suspicious LNK Persistence Dropped in Startup Folder
Suspicious LNK File Created In Startup Folder For Persistence
Suspicious OCEANMAP EdgeContext.url Startup Persistence (via file_event)
Suspicious HealthApp Batch File Persistence in Start Menu Startup Folder
Pivot detection · T1547.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.