Suspicious Search-ms URI Handler Abuse to Remote Share

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-29
Updated
2026-09-29

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects command lines invoking the search-ms protocol handler with a remote location parameter, a technique that presents attacker-hosted SMB shares as local search results to trick users into launching malware disguised as documents. This was observed in a fake AnyDesk lure where an LNK masqueraded as a PDF. Search-ms abuse pointing to a remote share is a hallmark of social-engineered initial access.

Related detections9 linkedT1036.005 — drag to rearrange
Proxy Web Requests for Flash Player Installer from Unofficial Locations
Suspicious Run Key Persistence With Masqueraded System Binary by Millenium RAT (via registry_set)
Malicious MuddyWater Named Payload Execution from ProgramData and Public Paths (via process_creation)
Malicious Masquerading via IEXPLORE.EXE OriginalFileName on Unexpected Image (via process_creation)
Malicious DeadLock Ransomware Dropper Masquerading as svhost.exe (via process_creation)
Suspicious Masquerading Scheduled Task Impersonating Microsoft Edge Update
Suspicious PowerShell String Concatenation Obfuscation for Batch Extension via LNK (via process_creation)
Malicious Ransomware Payload Execution via HWP Word Processor Spawning Executable from Temp
Malicious RoKRAT Staged Loader Files in Temp via LNK (via file_event)
Suspicious Search-ms URI Handler Abuse to Remote Share
Pivot detection · T1036.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.