Windows hh.exe Execution with .chm Command-Line

Flags hh.exe being executed with a command line referencing a .chm file on Windows.

FreeUnreviewedSigmalowv1
title: Windows hh.exe Execution with .chm Command-Line
id: f3ad8d85-d858-478a-85b9-6f3c1d997e1b
status: test
description: This rule identifies process creation events where hh.exe (winhlp32 HTML Help executable) is launched with a command line containing “.chm”. Attackers may use this pattern to open HTML Help content in ways that can facilitate stealthy execution or lure user interaction. It relies on Windows process creation telemetry with fields for the original executable name, image path, and command line content.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1218.001/T1218.001.md
  - https://eqllib.readthedocs.io/en/latest/analytics/b25aa548-7937-11e9-8f5c-d46d6d62a49e.html
  - https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml
author: E.M. Anhaus (originally from Atomic Blue Detections, Dan Beavin), oscd.community, Huntrule Team
date: 2019-10-24
modified: 2023-12-11
tags:
  - attack.stealth
  - attack.t1218.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - OriginalFileName: HH.exe
    - Image|endswith: \hh.exe
  selection_cli:
    CommandLine|contains: .chm
  condition: all of selection_*
falsepositives:
  - False positives are expected with legitimate ".CHM"
level: low
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_hh_chm_execution/info.yml
license: DRL-1.1
related:
  - id: 68c8acb4-1b60-4890-8e82-3ddf7a6dba84
    type: derived

What it detects

This rule identifies process creation events where hh.exe (winhlp32 HTML Help executable) is launched with a command line containing “.chm”. Attackers may use this pattern to open HTML Help content in ways that can facilitate stealthy execution or lure user interaction. It relies on Windows process creation telemetry with fields for the original executable name, image path, and command line content.

Known false positives

  • False positives are expected with legitimate ".CHM"

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.