Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators

Alerts on Windows RunMRU registry changes containing HTTP/HTTPS URLs plus captcha/automation or command execution indicators.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-03-25
Updated
2026-07-30
title: Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators
id: a1e0babf-471a-429a-a736-4c88fd180529
related:
  - id: d487ed4a-fd24-436d-a0b2-f4e95f7b2635
    type: similar
  - id: f5fe36cf-f1ec-4c23-903d-09a3110f6bbb
    type: derived
status: experimental
description: This rule flags Windows registry Set operations targeting Explorer RunMRU entries where the stored Details contain HTTP or HTTPS URLs. It further narrows matches to entries that include common fake-interaction and automation-bypass terms (for example, captcha/challenge/verification) and/or strings associated with command or scripting execution tools (such as PowerShell, cmd, mshta, certutil, curl, wget, and mshta). This combination matters because it can reflect user-driven phishing lure workflows that lead to pasting and executing attacker-controlled content via the Run dialog. The detection relies on registry_set telemetry for RunMRU TargetObject and the presence of specific URL and keyword patterns in the Details field.
references:
  - https://github.com/JohnHammond/recaptcha-phish
  - https://www.zscaler.com/blogs/security-research/deepseek-lure-using-captchas-spread-malware
  - https://www.threatdown.com/blog/clipboard-hijacker-tries-to-install-a-trojan/
  - https://app.any.run/tasks/5c16b4db-4b36-4039-a0ed-9b09abff8be2
  - https://www.esentire.com/security-advisories/netsupport-rat-clickfix-distribution
  - https://medium.com/@boutnaru/the-windows-foreniscs-journey-run-mru-run-dialog-box-most-recently-used-57375a02d724
  - https://unit42.paloaltonetworks.com/preventing-clickfix-attack-vector/
  - https://medium.com/@poudelswachchhanda123/preventing-lnk-and-fakecaptcha-threats-a-system-hardening-approach-2f7b7ed2e493
  - https://www.scpx.com.au/2025/11/16/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_potential_clickfix_execution.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-03-25
modified: 2025-11-19
tags:
  - attack.execution
  - attack.t1204.001
logsource:
  category: registry_set
  product: windows
detection:
  selection_registry:
    TargetObject|contains: \SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\
  selection_details:
    Details|contains:
      - http://
      - https://
  selection_susp_pattern:
    - Details|contains:
        - account
        - anti-bot
        - botcheck
        - captcha
        - challenge
        - confirmation
        - fraud
        - human
        - identification
        - identificator
        - identity
        - robot
        - validation
        - verification
        - verify
    - Details|contains:
        - "%comspec%"
        - bitsadmin
        - certutil
        - cmd
        - cscript
        - curl
        - finger
        - mshta
        - powershell
        - pwsh
        - regsvr32
        - rundll32
        - schtasks
        - wget
        - wscript
  condition: all of selection_*
falsepositives:
  - Legitimate applications using RunMRU with HTTP links
level: high
license: DRL-1.1