PowerShell COM CLSID Download Cradles: Suspicious GetTypeFromCLSID Usage

Alerts on PowerShell script blocks using GetTypeFromCLSID with specific CLSIDs indicative of COM-based download cradles.

FreeUnreviewedSigmamediumv1
title: "PowerShell COM CLSID Download Cradles: Suspicious GetTypeFromCLSID Usage"
id: 4e030809-6475-4312-8f7b-8a1d0206f26d
related:
  - id: 02b64f1b-3f33-4e67-aede-ef3b0a5a8fcf
    type: similar
  - id: 3c7d1587-3b13-439f-9941-7d14313dbdfe
    type: derived
status: test
description: This rule flags PowerShell script blocks that call [Type]::GetTypeFromCLSID and include specific CLSIDs commonly associated with COM objects that can be used as download cradles. Such behavior matters because attackers can use COM object instantiation to obtain remote payloads while blending into legitimate scripting patterns. The detection relies on Script Block Logging telemetry, matching the presence of GetTypeFromCLSID and the listed CLSIDs within the same script block text.
references:
  - https://learn.microsoft.com/en-us/dotnet/api/system.type.gettypefromclsid?view=net-7.0
  - https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=57
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_download_com_cradles.yml
author: frack113, Huntrule Team
date: 2022-12-25
tags:
  - attack.command-and-control
  - attack.t1105
logsource:
  product: windows
  category: ps_script
  definition: Script Block Logging must be enable
detection:
  selection_1:
    ScriptBlockText|contains: "[Type]::GetTypeFromCLSID("
  selection_2:
    ScriptBlockText|contains:
      - 0002DF01-0000-0000-C000-000000000046
      - F6D90F16-9C73-11D3-B32E-00C04F990BB4
      - F5078F35-C551-11D3-89B9-0000F81FE221
      - 88d96a0a-f192-11d4-a65f-0040963251e5
      - AFBA6B42-5692-48EA-8141-DC517DCF0EF1
      - AFB40FFD-B609-40A3-9828-F88BBE11E4E3
      - 88d96a0b-f192-11d4-a65f-0040963251e5
      - 2087c2f4-2cef-4953-a8ab-66779b670495
      - 000209FF-0000-0000-C000-000000000046
      - 00024500-0000-0000-C000-000000000046
  condition: all of selection_*
falsepositives:
  - Legitimate use of the library
level: medium
license: DRL-1.1

What it detects

This rule flags PowerShell script blocks that call [Type]::GetTypeFromCLSID and include specific CLSIDs commonly associated with COM objects that can be used as download cradles. Such behavior matters because attackers can use COM object instantiation to obtain remote payloads while blending into legitimate scripting patterns. The detection relies on Script Block Logging telemetry, matching the presence of GetTypeFromCLSID and the listed CLSIDs within the same script block text.

Known false positives

  • Legitimate use of the library

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.