PowerShell COM CLSID Download Cradles: Suspicious GetTypeFromCLSID Usage
Alerts on PowerShell script blocks using GetTypeFromCLSID with specific CLSIDs indicative of COM-based download cradles.
FreeUnreviewedSigmamediumv1
powershell-com-clsid-download-cradles-suspicious-gettypefromclsid-usage-3c7d1587
title: "PowerShell COM CLSID Download Cradles: Suspicious GetTypeFromCLSID Usage"
id: 4e030809-6475-4312-8f7b-8a1d0206f26d
related:
- id: 02b64f1b-3f33-4e67-aede-ef3b0a5a8fcf
type: similar
- id: 3c7d1587-3b13-439f-9941-7d14313dbdfe
type: derived
status: test
description: This rule flags PowerShell script blocks that call [Type]::GetTypeFromCLSID and include specific CLSIDs commonly associated with COM objects that can be used as download cradles. Such behavior matters because attackers can use COM object instantiation to obtain remote payloads while blending into legitimate scripting patterns. The detection relies on Script Block Logging telemetry, matching the presence of GetTypeFromCLSID and the listed CLSIDs within the same script block text.
references:
- https://learn.microsoft.com/en-us/dotnet/api/system.type.gettypefromclsid?view=net-7.0
- https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=57
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_download_com_cradles.yml
author: frack113, Huntrule Team
date: 2022-12-25
tags:
- attack.command-and-control
- attack.t1105
logsource:
product: windows
category: ps_script
definition: Script Block Logging must be enable
detection:
selection_1:
ScriptBlockText|contains: "[Type]::GetTypeFromCLSID("
selection_2:
ScriptBlockText|contains:
- 0002DF01-0000-0000-C000-000000000046
- F6D90F16-9C73-11D3-B32E-00C04F990BB4
- F5078F35-C551-11D3-89B9-0000F81FE221
- 88d96a0a-f192-11d4-a65f-0040963251e5
- AFBA6B42-5692-48EA-8141-DC517DCF0EF1
- AFB40FFD-B609-40A3-9828-F88BBE11E4E3
- 88d96a0b-f192-11d4-a65f-0040963251e5
- 2087c2f4-2cef-4953-a8ab-66779b670495
- 000209FF-0000-0000-C000-000000000046
- 00024500-0000-0000-C000-000000000046
condition: all of selection_*
falsepositives:
- Legitimate use of the library
level: medium
license: DRL-1.1
What it detects
This rule flags PowerShell script blocks that call [Type]::GetTypeFromCLSID and include specific CLSIDs commonly associated with COM objects that can be used as download cradles. Such behavior matters because attackers can use COM object instantiation to obtain remote payloads while blending into legitimate scripting patterns. The detection relies on Script Block Logging telemetry, matching the presence of GetTypeFromCLSID and the listed CLSIDs within the same script block text.
Known false positives
- Legitimate use of the library
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.