Name:Windows Content Copied from Browser was Executed id:5d1fdbcb-5ed9-4190-85c8-7f9026450a0b version:1 date:None author:Onur Mustafa Erdogan, Splunk status:production type:TTP Description:The following analytic correlates modifications to the Windows RunMRU registry key with clipboard content
changes initiated by browsers. It aims to detect ClickFix scenarios in which commands copied
from a browser are subsequently executed on the Windows system through the Run dialog box. Data_source:
how_to_implement:This detection requires Sysmon event logs. Configure your environment to ingest Sysmon registry modification (Event ID 13)
and clipboard change (Event ID 24) events. Ensure that registry modification events are collected for the RunMRU registry key
and clipboard change events are collected from common browser processes. Ingest the data through the appropriate Splunk technology
add-on and normalize field names using the Splunk Common Information Model (CIM). known_false_positives:No false positives have been identified at this time. References: -https://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/ -https://www.huntress.com/blog/clickfix-matanbuchus-astarionrat-analysis drilldown_searches: name:'View the detection results for - "$dest$"' search:'%original_detection_search% | search dest = "$dest$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$dest$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Fake CAPTCHA Campaigns']