FileFix - Command Evidence in TypedPaths

 Original Source: [Sigma source]
Title: FileFix - Command Evidence in TypedPaths
Status: experimental
Description:Detects commonly-used chained commands and strings in the most recent 'url' value of the 'TypedPaths' key, which could be indicative of a user being targeted by the FileFix technique.
References:
  -https://x.com/russianpanda9xx/status/1940831134759506029
  -https://mrd0x.com/filefix-clickfix-alternative/
  -https://www.scpx.com.au/2025/11/16/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/
Author: Alfie Champion (delivr.to), Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-07-05
modified:2025-11-19
Tags:
  • -'attack.execution'
  • -'attack.t1204.004'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection_base:
    TargetObject|endswith: '\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths\url1'
    Details|contains|all:
      -'#'
      -'http'

  selection_cmd:
    - Details|contains:
      - 'account'
      - 'anti-bot'
      - 'botcheck'
      - 'captcha'
      - 'challenge'
      - 'confirmation'
      - 'fraud'
      - 'human'
      - 'identification'
      - 'identificator'
      - 'identity'
      - 'robot'
      - 'validation'
      - 'verification'
      - 'verify'
    - Details|contains:
      - '%comspec%'
      - 'bitsadmin'
      - 'certutil'
      - 'cmd'
      - 'cscript'
      - 'curl'
      - 'finger'
      - 'mshta'
      - 'powershell'
      - 'pwsh'
      - 'regsvr32'
      - 'rundll32'
      - 'schtasks'
      - 'wget'
      - 'wscript'
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high