Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent

Flags Windows process creation where EQNEDT32.EXE is the parent, matching CVE-2017-11882 exploitation dropper behavior.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-11-23
Updated
2026-07-31

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creations where the parent process path ends with EQNEDT32.EXE, consistent with exploitation and dropper behavior associated with CVE-2017-11882. EQNEDT32.EXE spawning additional processes can indicate an attacker has executed an Office-related exploit path to launch further payload stages. It relies on Windows process creation telemetry that includes ParentImage and process path information.

Related detections9 linkedT1203 — drag to rearrange
Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Malicious Script Execution from WinRAR Extraction Directory via CVE-2023-38831
Suspicious DLL Written to Explorer IconCache Path
Malicious Microsoft Word Spawning Anomalous Child Process via CVE-2023-36884 (via process_creation)
Malicious Equation Editor Child Process Execution via process_creation
Ursnif C2 Proxy Traffic Identified by Base64 URI Encoding and .avi/.images Pattern
Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Proxy downloads of executable and document files from suspicious TLDs (blacklisted domains)
Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Pivot detection · T1203 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.