Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators
Alerts on Windows RunMRU registry changes containing HTTP/HTTPS URLs plus captcha/automation or command execution indicators.
- Product
- windows
- Category
- registry_set
- Author
- Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2025-03-25
- Updated
- 2026-07-30
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows registry Set operations targeting Explorer RunMRU entries where the stored Details contain HTTP or HTTPS URLs. It further narrows matches to entries that include common fake-interaction and automation-bypass terms (for example, captcha/challenge/verification) and/or strings associated with command or scripting execution tools (such as PowerShell, cmd, mshta, certutil, curl, wget, and mshta). This combination matters because it can reflect user-driven phishing lure workflows that lead to pasting and executing attacker-controlled content via the Run dialog. The detection relies on registry_set telemetry for RunMRU TargetObject and the presence of specific URL and keyword patterns in the Details field.
Reporting behind it
- github.comhttps://github.com/JohnHammond/recaptcha-phish
- zscaler.comhttps://www.zscaler.com/blogs/security-research/deepseek-lure-using-captchas-spread-malware
- threatdown.comhttps://www.threatdown.com/blog/clipboard-hijacker-tries-to-install-a-trojan/
- app.any.runhttps://app.any.run/tasks/5c16b4db-4b36-4039-a0ed-9b09abff8be2
- esentire.comhttps://www.esentire.com/security-advisories/netsupport-rat-clickfix-distribution
- medium.comhttps://medium.com/@boutnaru/the-windows-foreniscs-journey-run-mru-run-dialog-box-most-recently-used-57375a02d724
- unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/preventing-clickfix-attack-vector/
- medium.comhttps://medium.com/@poudelswachchhanda123/preventing-lnk-and-fakecaptcha-threats-a-system-hardening-approach-2f7b7ed2e493
- scpx.com.auhttps://www.scpx.com.au/2025/11/16/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_potential_clickfix_execution.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators
id: a1e0babf-471a-429a-a736-4c88fd180529
related:
- id: d487ed4a-fd24-436d-a0b2-f4e95f7b2635
type: similar
- id: f5fe36cf-f1ec-4c23-903d-09a3110f6bbb
type: derived
status: experimental
description: This rule flags Windows registry Set operations targeting Explorer RunMRU entries where the stored Details contain HTTP or HTTPS URLs. It further narrows matches to entries that include common fake-interaction and automation-bypass terms (for example, captcha/challenge/verification) and/or strings associated with command or scripting execution tools (such as PowerShell, cmd, mshta, certutil, curl, wget, and mshta). This combination matters because it can reflect user-driven phishing lure workflows that lead to pasting and executing attacker-controlled content via the Run dialog. The detection relies on registry_set telemetry for RunMRU TargetObject and the presence of specific URL and keyword patterns in the Details field.
references:
- https://github.com/JohnHammond/recaptcha-phish
- https://www.zscaler.com/blogs/security-research/deepseek-lure-using-captchas-spread-malware
- https://www.threatdown.com/blog/clipboard-hijacker-tries-to-install-a-trojan/
- https://app.any.run/tasks/5c16b4db-4b36-4039-a0ed-9b09abff8be2
- https://www.esentire.com/security-advisories/netsupport-rat-clickfix-distribution
- https://medium.com/@boutnaru/the-windows-foreniscs-journey-run-mru-run-dialog-box-most-recently-used-57375a02d724
- https://unit42.paloaltonetworks.com/preventing-clickfix-attack-vector/
- https://medium.com/@poudelswachchhanda123/preventing-lnk-and-fakecaptcha-threats-a-system-hardening-approach-2f7b7ed2e493
- https://www.scpx.com.au/2025/11/16/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_potential_clickfix_execution.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-03-25
modified: 2025-11-19
tags:
- attack.execution
- attack.t1204.001
logsource:
category: registry_set
product: windows
detection:
selection_registry:
TargetObject|contains: \SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\
selection_details:
Details|contains:
- http://
- https://
selection_susp_pattern:
- Details|contains:
- account
- anti-bot
- botcheck
- captcha
- challenge
- confirmation
- fraud
- human
- identification
- identificator
- identity
- robot
- validation
- verification
- verify
- Details|contains:
- "%comspec%"
- bitsadmin
- certutil
- cmd
- cscript
- curl
- finger
- mshta
- powershell
- pwsh
- regsvr32
- rundll32
- schtasks
- wget
- wscript
condition: all of selection_*
falsepositives:
- Legitimate applications using RunMRU with HTTP links
level: high
license: DRL-1.1