This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
FileFix - Command Evidence in TypedPaths
Original Source:
[Sigma source]
Title:
FileFix - Command Evidence in TypedPaths
Status:
experimental
Description:
Detects commonly-used chained commands and strings in the most recent 'url' value of the 'TypedPaths' key, which could be indicative of a user being targeted by the FileFix technique.
References:
-https://x.com/russianpanda9xx/status/1940831134759506029
-https://mrd0x.com/filefix-clickfix-alternative/
-https://www.scpx.com.au/2025/11/16/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/
Author:
Alfie Champion (delivr.to), Swachchhanda Shrawan Poudel (Nextron Systems)
Date:
2025-07-05
modified:
2025-11-19
Tags:
-'attack.execution'
-'attack.t1204.004'
Logsource:
category: registry_set
product: windows
Detection:
selection_base:
TargetObject|endswith
:
'\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths\url1'
Details|contains|all
:
-'#'
-'http'
selection_cmd:
- Details|contains
:
- 'account'
- 'anti-bot'
- 'botcheck'
- 'captcha'
- 'challenge'
- 'confirmation'
- 'fraud'
- 'human'
- 'identification'
- 'identificator'
- 'identity'
- 'robot'
- 'validation'
- 'verification'
- 'verify'
- Details|contains
:
- '%comspec%'
- 'bitsadmin'
- 'certutil'
- 'cmd'
- 'cscript'
- 'curl'
- 'finger'
- 'mshta'
- 'powershell'
- 'pwsh'
- 'regsvr32'
- 'rundll32'
- 'schtasks'
- 'wget'
- 'wscript'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
high