Windows Registry Persistence via hhctrl CLSID InprocServer32 Default Modification
Flags registry changes to the hhctrl COM CLSID InprocServer32 (Default) to load a custom binary instead of the system hhctrl.ocx.
FreeUnreviewedSigmahighv1
windows-registry-persistence-via-hhctrl-clsid-inprocserver32-default-modificatio-f10ed525
title: Windows Registry Persistence via hhctrl CLSID InprocServer32 Default Modification
id: 7459764c-268e-471e-b169-1a199a3f88c2
status: test
description: This rule identifies when the registry value under the hhctrl COM CLSID InprocServer32 (Default) is modified to point to a non-System32 binary. Attackers use this technique to persist by loading a custom COM server component when the system or applications instantiate the CLSID. It relies on Windows registry set telemetry for the specific TargetObject path and excludes the expected value pointing to C:\Windows\System32\hhctrl.ocx.
references:
- https://persistence-info.github.io/Data/hhctrl.html
- https://www.hexacorn.com/blog/2018/04/23/beyond-good-ol-run-key-part-77/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_hhctrl_persistence.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-07-21
modified: 2023-08-17
tags:
- attack.persistence
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|contains: \CLSID\{52A2AAAE-085D-4187-97EA-8C30DB990436}\InprocServer32\(Default)
filter:
Details: C:\Windows\System32\hhctrl.ocx
condition: selection and not filter
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: f10ed525-97fe-4fed-be7c-2feecca941b1
type: derived
What it detects
This rule identifies when the registry value under the hhctrl COM CLSID InprocServer32 (Default) is modified to point to a non-System32 binary. Attackers use this technique to persist by loading a custom COM server component when the system or applications instantiate the CLSID. It relies on Windows registry set telemetry for the specific TargetObject path and excludes the expected value pointing to C:\Windows\System32\hhctrl.ocx.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.