Network Management

WIN-PROT-HMPA-MALWARE-HOLLOWPROCESS detected by Sophos during Website Maintenance

Sophos EDR is detecting WIN-PROT-HMPA-MALWARE-HOLLOWPROCESS when the WebsiteMaintenance.exe process starts.

First published date

6/4/2025 9:07 PM

Last published date

8/6/2025 7:17 PM

Overview

During the scheduling of website maintenance, processes in WebsiteMaintenance.exe, ExportToPdfCmd.exe, SolarWinds.Administration.exe, w3wp.exe, and rundll32.exe are flagged as HollowProcess.

Windows Application Event Log:


Mitigation   HollowProcess V2
Policy       HollowProcessGuard

Platform     10.0.20348/x64 v803 06_55*
....
Application  C:\Program Files\SolarWinds\Orion\ExportToPDFCmd.Exe
Created      2025-05-23T15:23:34
Modified     2025-05-23T15:23:34
Description  ExportToPdfCmd 2025.2.0.2476+ad82881679


Symptoms:

  • The "SolarWinds Orion Application Pool" keeps stopping and needs to be restarted
  • Application Pool 'SolarWinds Orion Application Pool' is being automatically disabled due to a series of failures in the process(es) serving that application pool.

Product section

Orion Platform

Cause

This process is the default behavior of using Chromium Embedded Framework (CEF). It is used in multiple modules across SWOSH - ExportToPDF, Installer, BusinessLayerHost, w3wp, eowp, SolarWinds.Administration and rundll32.

These processes typically run as an IIS APPPOOL\SolarWinds Orion Application Pool user.

Resolution

Sophos validated that this is a false positive. Sophos advises customers that they may whitelist the detection ID against the affected SolarWinds process during website maintenance, at their discretion.

For more information, refer to the following Sophos article.