Windows Hwp.exe Spawned gbb.exe Subprocess Detection

Alerts when Hwp.exe launches gbb.exe, a suspicious child process pattern on Windows.

FreeUnreviewedSigmahighv1
title: Windows Hwp.exe Spawned gbb.exe Subprocess Detection
id: ad5f1b57-3623-4176-a397-6c4931b8e06a
status: test
description: This rule flags Windows process creation events where a Hangul Word Processor executable (Hwp.exe) spawns a subprocess named gbb.exe. Attackers may use HWP as an initial foothold and then launch additional executables to carry out malicious actions or exploitation. It relies on process creation telemetry that provides parent and child image paths to match the specific parent-child executable relationship.
references:
  - https://www.securitynewspaper.com/2016/11/23/technical-teardown-exploit-malware-hwp-files/
  - https://www.hybrid-analysis.com/search?query=context:74940dcc5b38f9f9b1a0fea760d344735d7d91b610e6d5bd34533dd0153402c5&from_sample=5db135000388385a7644131f&block_redirect=1
  - https://twitter.com/cyberwar_15/status/1187287262054076416
  - https://blog.alyac.co.kr/1901
  - https://en.wikipedia.org/wiki/Hangul_(word_processor)
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hwp_exploits.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2019-10-24
modified: 2021-11-27
tags:
  - attack.initial-access
  - attack.t1566.001
  - attack.execution
  - attack.t1203
  - attack.t1059.003
  - attack.g0032
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith: \Hwp.exe
    Image|endswith: \gbb.exe
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 023394c4-29d5-46ab-92b8-6a534c6f447b
    type: derived

What it detects

This rule flags Windows process creation events where a Hangul Word Processor executable (Hwp.exe) spawns a subprocess named gbb.exe. Attackers may use HWP as an initial foothold and then launch additional executables to carry out malicious actions or exploitation. It relies on process creation telemetry that provides parent and child image paths to match the specific parent-child executable relationship.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.