Detection rules › Splunk

Suspicious Child Process for hh.exe (Sysmon)

Group by
_time, host
Source
github.com/anvilogic-forge/armory

Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code. CHM files are commonly distributed as part of the Microsoft HTML Help system. A custom CHM file containing embedded payloads could be delivered to a victim then triggered by User Execution. This use case detects hh.exe spawning suspicious child processes, including shell utilities and other native Windows utilities

MITRE ATT&CK coverage

References

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 1: Process creation

Rule body

id: '17798.30045'
title: Suspicious Child Process for hh.exe
description: 'Adversaries may abuse Compiled HTML files (.chm) to conceal malicious
  code. CHM files are commonly distributed as part of the Microsoft HTML Help system.
  A custom CHM file containing embedded payloads could be delivered to a victim then
  triggered by User Execution. This use case detects hh.exe spawning suspicious child
  processes, including shell utilities and other native Windows utilities. -- Threat
  Actor Association: APT-K-47/Mysterious Elephant -- LOLBAS Atomics T1218.001 Test
  #2'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=1) OR "<EventID>1<")
  (TERM(hh) OR "hh.exe") (TERM(cmd) OR TERM(powershell) OR TERM(pwsh) OR TERM(wscript)
  OR TERM(cscript) OR TERM(regsvr32) OR TERM(wmic) OR TERM(rundll32) OR TERM(MSHTA)
  OR TERM(CertUtil) OR TERM(CertReq) OR TERM(MSbuild) OR TERM(installutil) OR TERM(schtasks)
  OR TERM(msiexec)) | where match(parent_process_name, "(?i)hh\.exe") and match(process_name,
  "(?i)cmd|powershell|pwsh|wscript|cscript|regsvr32|wmic|rundll32|MSHTA|CertUtil|CertReq|MSbuild|installutil|schtasks|msiexec")
  | table _time, host, user process, process_*, parent_process_* | bin span=1s | stats
  values(*) as * by _time, host '
techniques:
- defense-evasion:system binary proxy execution:compiled html file
technique_id:
- T1218.001
data_category:
- Windows Sysmon
references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.001/T1218.001.md#atomic-test-2---compiled-html-help-remote-payload
- https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=1) OR "<EventID>1<") (TERM(hh) OR "hh.exe") (TERM(cmd) OR TERM(powershell) OR TERM(pwsh) OR TERM(wscript) OR TERM(cscript) OR TERM(regsvr32) OR TERM(wmic) OR TERM(rundll32) OR TERM(MSHTA) OR TERM(CertUtil) OR TERM(CertReq) OR TERM(MSbuild) OR TERM(installutil) OR TERM(schtasks) OR TERM(msiexec))

Stage 2: where

| where match(parent_process_name, "(?i)hh\.exe") and match(process_name, "(?i)cmd|powershell|pwsh|wscript|cscript|regsvr32|wmic|rundll32|MSHTA|CertUtil|CertReq|MSbuild|installutil|schtasks|msiexec")

Stage 3: table

| table _time, host, user process, process_*, parent_process_*

Stage 4: bucket

| bin span=1s

Stage 5: stats

| stats values(*) as * by _time, host

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
EventCodeeq
  • 1 corpus 241 (splunk 225, kusto 15, elastic 1)
field:"EventID" kind:eq value:"1"
parent_process_nameregex_match
  • "(?i)hh.exe" corpus 2 (splunk 2)
field:"parent_process_name" kind:regex_match
process_nameregex_match
    • "(?i)cmd
    • powershell
    • pwsh
    • wscript
    • cscript
    • regsvr32
    • wmic
    • rundll32
    • MSHTA
    • CertUtil
    • CertReq
    • MSbuild
    • installutil
    • schtasks
    • msiexec"
    corpus 2 (splunk 2)
field:"process_name" kind:regex_match

Search terms

These SPL tokens match against raw event text.

StageTerm
1"<EventID>1<"
1hh
1"hh.exe"
1cmd
1powershell
1pwsh
1wscript
1cscript
1regsvr32
1wmic
1rundll32
1MSHTA
1CertUtil
1CertReq
1MSbuild
1installutil
1schtasks
1msiexec