Network Management
WIN-PROT-HMPA-MALWARE-HOLLOWPROCESS detected by Sophos during Website Maintenance
Sophos EDR is detecting WIN-PROT-HMPA-MALWARE-HOLLOWPROCESS when the WebsiteMaintenance.exe process starts.
First published date
Last published date
Overview
During the scheduling of website maintenance, processes in WebsiteMaintenance.exe, ExportToPdfCmd.exe, SolarWinds.Administration.exe, w3wp.exe, and rundll32.exe are flagged as HollowProcess.
Windows Application Event Log:
Mitigation HollowProcess V2
Policy HollowProcessGuard
Platform 10.0.20348/x64 v803 06_55*
....
Application C:\Program Files\SolarWinds\Orion\ExportToPDFCmd.Exe
Created 2025-05-23T15:23:34
Modified 2025-05-23T15:23:34
Description ExportToPdfCmd 2025.2.0.2476+ad82881679
Symptoms:
- The "SolarWinds Orion Application Pool" keeps stopping and needs to be restarted
- Application Pool 'SolarWinds Orion Application Pool' is being automatically disabled due to a series of failures in the process(es) serving that application pool.
Product section
Cause
This process is the default behavior of using Chromium Embedded Framework (CEF). It is used in multiple modules across SWOSH - ExportToPDF, Installer, BusinessLayerHost, w3wp, eowp, SolarWinds.Administration and rundll32.
These processes typically run as an IIS APPPOOL\SolarWinds Orion Application Pool user.
Resolution
Sophos validated that this is a false positive. Sophos advises customers that they may whitelist the detection ID against the affected SolarWinds process during website maintenance, at their discretion.
For more information, refer to the following Sophos article.