Windows Registry Persistence via hhctrl CLSID InprocServer32 Default Modification

Flags registry changes to the hhctrl COM CLSID InprocServer32 (Default) to load a custom binary instead of the system hhctrl.ocx.

FreeUnreviewedSigmahighv1
title: Windows Registry Persistence via hhctrl CLSID InprocServer32 Default Modification
id: 7459764c-268e-471e-b169-1a199a3f88c2
status: test
description: This rule identifies when the registry value under the hhctrl COM CLSID InprocServer32 (Default) is modified to point to a non-System32 binary. Attackers use this technique to persist by loading a custom COM server component when the system or applications instantiate the CLSID. It relies on Windows registry set telemetry for the specific TargetObject path and excludes the expected value pointing to C:\Windows\System32\hhctrl.ocx.
references:
  - https://persistence-info.github.io/Data/hhctrl.html
  - https://www.hexacorn.com/blog/2018/04/23/beyond-good-ol-run-key-part-77/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_hhctrl_persistence.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-07-21
modified: 2023-08-17
tags:
  - attack.persistence
logsource:
  category: registry_set
  product: windows
detection:
  selection:
    TargetObject|contains: \CLSID\{52A2AAAE-085D-4187-97EA-8C30DB990436}\InprocServer32\(Default)
  filter:
    Details: C:\Windows\System32\hhctrl.ocx
  condition: selection and not filter
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: f10ed525-97fe-4fed-be7c-2feecca941b1
    type: derived

What it detects

This rule identifies when the registry value under the hhctrl COM CLSID InprocServer32 (Default) is modified to point to a non-System32 binary. Attackers use this technique to persist by loading a custom COM server component when the system or applications instantiate the CLSID. It relies on Windows registry set telemetry for the specific TargetObject path and excludes the expected value pointing to C:\Windows\System32\hhctrl.ocx.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.