Change Default File Association

T1546.001

Sub-technique of T1546 Event Triggered Execution.View on attack.mitre.org

About this technique

Adversaries may establish persistence by executing malicious content triggered by a file type association. When a file is opened, the default program used to open the file (also called the file association or handler) is checked. File association selections are stored in the Windows Registry and can be edited by users, administrators, or programs that have Registry access or by administrators using the built-in assoc utility. Applications can modify the file association for a given file extension to call an arbitrary program when a file with the given extension is opened.

System file associations are listed under HKEY_CLASSES_ROOT\.[extension], for example HKEY_CLASSES_ROOT\.txt. The entries point to a handler for that extension located at HKEY_CLASSES_ROOT\\[handler]. The various commands are then listed as subkeys underneath the shell key at HKEY_CLASSES_ROOT\\[handler]\shell\\[action]\command. For example:

* HKEY_CLASSES_ROOT\txtfile\shell\open\command
* HKEY_CLASSES_ROOT\txtfile\shell\print\command
* HKEY_CLASSES_ROOT\txtfile\shell\printto\command

The values of the keys listed are commands that are executed when the handler opens the file extension. Adversaries can modify these values to continually execute arbitrary commands.

Detection rules10

Rules on DetectionCode tagged with T1546.001.

Sigma5

RuleLevelLog source
Change Default File Association To Executable Via Assochighwindows / process_creation
Shell Open Registry Keys Manipulationhighwindows / registry_event
Registry Modification of MS-settings Protocol Handlermediumwindows / process_creation
Suspicious Shell Open Command Registry Modificationmediumwindows / registry_set
Change Default File Association Via Assoclowwindows / process_creation

Splunk5

RuleTypeRiskData source
Change Default File AssociationTTPNULLSysmon EventID 12, Sysmon EventID 13
Suspicious Changes to File AssociationsTTPNULLSysmon EventID 1
Windows Change Default File Association For No File ExtTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Change File Association Command To NotepadTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows New Default File Association Value SetHuntingNULLSysmon EventID 13

Groups1

Software1

Campaigns0

None recorded.

Procedure examples2

Groups1

Used byProcedure example
GroupKimsuky

Kimsuky has a HWP document stealer module which changes the default program association in the registry to open HWP documents.

Software1

Used byProcedure example
ToolSILENTTRINITY

SILENTTRINITY can conduct an image hijack of an `.msc` file extension as part of its UAC bypass process.

References4

  1. Microsoft Assoc Oct 2017 Open source
    Plett, C. et al.. (2017, October 15). assoc. Retrieved August 7, 2018.
  2. Microsoft Change Default Programs Open source
    Microsoft. (n.d.). Change which programs Windows 7 uses by default. Retrieved July 26, 2016.
  3. Microsoft File Handlers Open source
    Microsoft. (n.d.). Specifying File Handlers for File Name Extensions. Retrieved September 12, 2024.
  4. TrendMicro TROJ-FAKEAV OCT 2012 Open source
    Sioting, S. (2012, October 8). TROJ_FAKEAV.GZD. Retrieved August 8, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.