{"id":"T1218.001","name":"Compiled HTML File","url":"https://attack.mitre.org/techniques/T1218/001","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0342","stix_id":"x-mitre-detection-strategy--fafb9522-c185-48e0-b0a5-e65887f5deb4","name":"Detection of Suspicious Compiled HTML File Execution via hh.exe","url":"https://attack.mitre.org/detectionstrategies/DET0342","analytics":[{"id":"AN0968","stix_id":"x-mitre-analytic--23e84bf6-70d1-4c49-97b8-0fff9c6efa8f","name":"Analytic 0968","description":"Execution of hh.exe to open a .chm file followed by suspicious child processes or script engine invocation (VBScript, JScript, mshta, powershell). Behavior includes loading a CHM file from untrusted locations, or immediately spawning commands indicative of payload execution.","url":"https://attack.mitre.org/detectionstrategies/DET0342#AN0968","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"CHMPathRegex","description":"Regex matching CHM file locations; tune to exclude trusted internal software help files"},{"field":"ChildProcessList","description":"List of suspicious children of hh.exe (powershell.exe, cmd.exe, mshta.exe, wscript.exe)"},{"field":"NetworkDestinationAllowlist","description":"Filter for legitimate update/help servers accessed by hh.exe"},{"field":"TimeWindow","description":"Threshold time between hh.exe execution and suspicious follow-on activity"}],"live":true,"detection_strategies":["DET0342"],"techniques":["T1218.001"]}],"live":true,"version":"1.0","techniques":["T1218.001"]}],"sigma_rules":[{"id":"468a8cea-2920-4909-a593-0cbe1d96674a","title":"HH.EXE Initiated HTTP Network Connection","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-10-05","modified":null,"description":"Detects a network connection initiated by the \"hh.exe\" process to HTTP destination ports, which could indicate the execution/download of remotely hosted .chm files.\n","references":["https://www.splunk.com/en_us/blog/security/follina-for-protocol-handlers.html","https://github.com/redcanaryco/atomic-red-team/blob/1cf4dd51f83dcb0ebe6ade902d6157ad2dbc6ac8/atomics/T1218.001/T1218.001.md"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.stealth","attack.t1218.001","detection.threat-hunting"],"path":"rules-threat-hunting/windows/network_connection/net_connection_win_hh_http_connection.yml","techniques":["T1218.001"],"cves":[]},{"id":"52cad028-0ff0-4854-8f67-d25dfcbc78b4","title":"HTML Help HH.EXE Suspicious Child Process","author":"Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2020-04-01","modified":"2023-04-12","description":"Detects a suspicious child process of a Microsoft HTML Help (HH.exe)","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/chm-badness-delivers-a-banking-trojan/","https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-27939090904026cc396b0b629c8e4314acd6f5dac40a676edbc87f4567b47eb7","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.stealth","attack.t1047","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.007","attack.t1218","attack.t1218.001","attack.t1218.010","attack.t1218.011","attack.t1566","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml","techniques":["T1047","T1059.001","T1059.003","T1059.005","T1059.007","T1218","T1218.001","T1218.010","T1218.011","T1566","T1566.001"],"cves":[]},{"id":"68c8acb4-1b60-4890-8e82-3ddf7a6dba84","title":"HH.EXE Execution","author":"E.M. Anhaus (originally from Atomic Blue Detections, Dan Beavin), oscd.community","status":"test","level":"low","date":"2019-10-24","modified":"2023-12-11","description":"Detects the execution of \"hh.exe\" to open \".chm\" files.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1218.001/T1218.001.md","https://eqllib.readthedocs.io/en/latest/analytics/b25aa548-7937-11e9-8f5c-d46d6d62a49e.html","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml","techniques":["T1218.001"],"cves":[]},{"id":"84b1706c-932a-44c4-ae28-892b28a25b94","title":"OneNote.EXE Execution of Malicious Embedded Scripts","author":"@kostastsale","status":"test","level":"high","date":"2023-02-02","modified":null,"description":"Detects the execution of malicious OneNote documents that contain embedded scripts.\nWhen a user clicks on a OneNote attachment and then on the malicious link inside the \".one\" file, it exports and executes the malicious embedded script from specific directories.\n","references":["https://bazaar.abuse.ch/browse/tag/one/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.001"],"path":"rules/windows/process_creation/proc_creation_win_office_onenote_embedded_script_execution.yml","techniques":["T1218.001"],"cves":[]},{"id":"e8a95b5e-c891-46e2-b33a-93937d3abc31","title":"Suspicious HH.EXE Execution","author":"Maxim Pavlunin","status":"test","level":"high","date":"2020-04-01","modified":"2023-04-12","description":"Detects a suspicious execution of a Microsoft HTML Help (HH.exe)","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/chm-badness-delivers-a-banking-trojan/","https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-27939090904026cc396b0b629c8e4314acd6f5dac40a676edbc87f4567b47eb7","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.stealth","attack.t1047","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.007","attack.t1218","attack.t1218.001","attack.t1218.010","attack.t1218.011","attack.t1566","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_susp_execution.yml","techniques":["T1047","T1059.001","T1059.003","T1059.005","T1059.007","T1218","T1218.001","T1218.010","T1218.011","T1566","T1566.001"],"cves":[]},{"id":"f57c58b3-ee69-4ef5-9041-455bf39aaa89","title":"Remote CHM File Download/Execution Via HH.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-09-29","modified":"2024-01-31","description":"Detects the usage of \"hh.exe\" to execute/download remotely hosted \".chm\" files.","references":["https://www.splunk.com/en_us/blog/security/follina-for-protocol-handlers.html","https://github.com/redcanaryco/atomic-red-team/blob/1cf4dd51f83dcb0ebe6ade902d6157ad2dbc6ac8/atomics/T1218.001/T1218.001.md","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_chm_remote_download_or_execution.yml","techniques":["T1218.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}