Windows hh.exe Execution with .chm Command-Line
Flags hh.exe being executed with a command line referencing a .chm file on Windows.
FreeUnreviewedSigmalowv1
windows-hh-exe-execution-with-chm-command-line-68c8acb4
title: Windows hh.exe Execution with .chm Command-Line
id: f3ad8d85-d858-478a-85b9-6f3c1d997e1b
status: test
description: This rule identifies process creation events where hh.exe (winhlp32 HTML Help executable) is launched with a command line containing “.chm”. Attackers may use this pattern to open HTML Help content in ways that can facilitate stealthy execution or lure user interaction. It relies on Windows process creation telemetry with fields for the original executable name, image path, and command line content.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1218.001/T1218.001.md
- https://eqllib.readthedocs.io/en/latest/analytics/b25aa548-7937-11e9-8f5c-d46d6d62a49e.html
- https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml
author: E.M. Anhaus (originally from Atomic Blue Detections, Dan Beavin), oscd.community, Huntrule Team
date: 2019-10-24
modified: 2023-12-11
tags:
- attack.stealth
- attack.t1218.001
logsource:
category: process_creation
product: windows
detection:
selection_img:
- OriginalFileName: HH.exe
- Image|endswith: \hh.exe
selection_cli:
CommandLine|contains: .chm
condition: all of selection_*
falsepositives:
- False positives are expected with legitimate ".CHM"
level: low
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_hh_chm_execution/info.yml
license: DRL-1.1
related:
- id: 68c8acb4-1b60-4890-8e82-3ddf7a6dba84
type: derived
What it detects
This rule identifies process creation events where hh.exe (winhlp32 HTML Help executable) is launched with a command line containing “.chm”. Attackers may use this pattern to open HTML Help content in ways that can facilitate stealthy execution or lure user interaction. It relies on Windows process creation telemetry with fields for the original executable name, image path, and command line content.
Known false positives
- False positives are expected with legitimate ".CHM"
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.