Windows Process and Registry Changes Associated with SOURGUM Actor Behaviors
Alerts on Windows process activity referencing specific system/IME WimBoot files and registry 'reg add' changes targeting HKLM CLSID inprocserver32.
FreeUnreviewedSigmahighv1
windows-process-and-registry-changes-associated-with-sourgum-actor-behaviors-7ba08e95
title: Windows Process and Registry Changes Associated with SOURGUM Actor Behaviors
id: 19be21a4-604b-4571-b01a-816e219d7604
status: test
description: This rule flags suspicious Windows process executions that reference specific system/IME/WimBoot configuration paths and perform registry modifications via commands containing 'reg add'. It also matches related registry targets under HKLM Class CLSID inprocserver32, which are commonly abused to alter COM-related execution behavior for persistence or privilege escalation. Detection relies on Windows process creation telemetry including the process Image path and CommandLine, as well as the registry paths and command content present in those events.
references:
- https://www.virustotal.com/gui/file/c299063e3eae8ddc15839767e83b9808fd43418dc5a1af7e4f44b97ba53fbd3d/detection
- https://github.com/Azure/Azure-Sentinel/blob/43e9be273dca321295190bfc4902858e009d4a35/Detections/MultipleDataSources/SOURGUM_IOC.yaml
- https://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/SOURGUM/proc_creation_win_apt_sourgrum.yml
author: MSTIC, FPT.EagleEye, Huntrule Team
date: 2021-06-15
modified: 2022-10-09
tags:
- attack.t1546
- attack.t1546.015
- attack.persistence
- attack.privilege-escalation
- detection.emerging-threats
logsource:
product: windows
category: process_creation
detection:
selection:
Image|contains:
- windows\system32\Physmem.sys
- Windows\system32\ime\SHARED\WimBootConfigurations.ini
- Windows\system32\ime\IMEJP\WimBootConfigurations.ini
- Windows\system32\ime\IMETC\WimBootConfigurations.ini
registry_image:
Image|contains:
- windows\system32\filepath2
- windows\system32\ime
CommandLine|contains: reg add
registry_key:
CommandLine|contains:
- HKEY_LOCAL_MACHINE\software\classes\clsid\{7c857801-7381-11cf-884d-00aa004b2e24}\inprocserver32
- HKEY_LOCAL_MACHINE\software\classes\clsid\{cf4cc405-e2c5-4ddd-b3ce-5e7582d8c9fa}\inprocserver32
condition: selection or all of registry_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 7ba08e95-1e0b-40cd-9db5-b980555e42fd
type: derived
What it detects
This rule flags suspicious Windows process executions that reference specific system/IME/WimBoot configuration paths and perform registry modifications via commands containing 'reg add'. It also matches related registry targets under HKLM Class CLSID inprocserver32, which are commonly abused to alter COM-related execution behavior for persistence or privilege escalation. Detection relies on Windows process creation telemetry including the process Image path and CommandLine, as well as the registry paths and command content present in those events.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.