Windows process and registry activity matching SOURGUM persistence/privilege escalation behavior

Alerts on Windows process activity referencing specific system/IME WimBoot files and registry 'reg add' changes targeting HKLM CLSID inprocserver32.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
MSTIC, FPT.EagleEye (SigmaHQ), DRL 1.1
Published
2021-06-15
Updated
2026-07-31
title: Windows process and registry activity matching SOURGUM persistence/privilege escalation behavior
id: 19be21a4-604b-4571-b01a-816e219d7604
status: test
description: This rule identifies suspicious Windows process creation and registry modification behavior associated with an actor tracked by Microsoft as SOURGUM. It matches processes that reference specific Windows system files or WimBoot configuration paths and also looks for reg.exe usage combined with targeted registry key patterns under HKEY_LOCAL_MACHINE. Such activity can indicate attempts to persist access or escalate privileges by altering in-process server registrations.
references:
  - https://www.virustotal.com/gui/file/c299063e3eae8ddc15839767e83b9808fd43418dc5a1af7e4f44b97ba53fbd3d/detection
  - https://github.com/Azure/Azure-Sentinel/blob/43e9be273dca321295190bfc4902858e009d4a35/Detections/MultipleDataSources/SOURGUM_IOC.yaml
  - https://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/SOURGUM/proc_creation_win_apt_sourgrum.yml
author: MSTIC, FPT.EagleEye, Huntrule Team
date: 2021-06-15
modified: 2022-10-09
tags:
  - attack.t1546
  - attack.t1546.015
  - attack.persistence
  - attack.privilege-escalation
  - detection.emerging-threats
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    Image|contains:
      - windows\system32\Physmem.sys
      - Windows\system32\ime\SHARED\WimBootConfigurations.ini
      - Windows\system32\ime\IMEJP\WimBootConfigurations.ini
      - Windows\system32\ime\IMETC\WimBootConfigurations.ini
  registry_image:
    Image|contains:
      - windows\system32\filepath2
      - windows\system32\ime
    CommandLine|contains: reg add
  registry_key:
    CommandLine|contains:
      - HKEY_LOCAL_MACHINE\software\classes\clsid\{7c857801-7381-11cf-884d-00aa004b2e24}\inprocserver32
      - HKEY_LOCAL_MACHINE\software\classes\clsid\{cf4cc405-e2c5-4ddd-b3ce-5e7582d8c9fa}\inprocserver32
  condition: selection or all of registry_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 7ba08e95-1e0b-40cd-9db5-b980555e42fd
    type: derived