{"id":"243380fa-11eb-4141-af92-e14925e77c1b","title":"Potential PSFactoryBuffer COM Hijacking","description":"Detects changes to the PSFactory COM InProcServer32 registry. This technique was used by RomCom to create persistence storing a malicious DLL.","author":"BlackBerry Threat Research and Intelligence Team - @Joseliyo_Jstnk","status":"test","level":"high","date":"2023-06-07","modified":"2023-08-17","tags":["attack.privilege-escalation","attack.persistence","attack.t1546.015"],"technique_ids":["T1546.015"],"logsource":{"category":"registry_set","product":"windows"},"falsepositives":["Unknown"],"references":["https://blogs.blackberry.com/en/2023/06/romcom-resurfaces-targeting-ukraine","https://strontic.github.io/xcyclopedia/library/clsid_C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6.html","https://www.virustotal.com/gui/file/6d3ab9e729bb03ae8ae3fcd824474c5052a165de6cb4c27334969a542c7b261d/detection","https://www.trendmicro.com/en_us/research/23/e/void-rabisu-s-use-of-romcom-backdoor-shows-a-growing-shift-in-th.html"],"source_path":"rules/windows/registry/registry_set/registry_set_persistence_comhijack_psfactorybuffer.yml","source_sha256":"04430e88a394e4b38ec128b3b8f4cdba13a59c1be641180b18e34e864b72b61f","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/registry/registry_set/registry_set_persistence_comhijack_psfactorybuffer.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Potential PSFactoryBuffer COM Hijacking\nid: 243380fa-11eb-4141-af92-e14925e77c1b\nstatus: test\ndescription: Detects changes to the PSFactory COM InProcServer32 registry. This technique was used by RomCom to create persistence storing a malicious DLL.\nreferences:\n    - https://blogs.blackberry.com/en/2023/06/romcom-resurfaces-targeting-ukraine\n    - https://strontic.github.io/xcyclopedia/library/clsid_C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6.html\n    - https://www.virustotal.com/gui/file/6d3ab9e729bb03ae8ae3fcd824474c5052a165de6cb4c27334969a542c7b261d/detection\n    - https://www.trendmicro.com/en_us/research/23/e/void-rabisu-s-use-of-romcom-backdoor-shows-a-growing-shift-in-th.html\nauthor: BlackBerry Threat Research and Intelligence Team - @Joseliyo_Jstnk\ndate: 2023-06-07\nmodified: 2023-08-17\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.t1546.015\nlogsource:\n    category: registry_set\n    product: windows\ndetection:\n    selection:\n        TargetObject|endswith: '\\CLSID\\{c90250f3-4d7d-4991-9b69-a5c5bc1c2ae6}\\InProcServer32\\(Default)'\n    filter_main:\n        Details:\n            - '%windir%\\System32\\ActXPrxy.dll'\n            - 'C:\\Windows\\System32\\ActXPrxy.dll'\n    condition: selection and not filter_main\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1546.015","id":"T1546.015","name":"Component Object Model Hijacking","page":"techniques/enterprise/T1546.015/"}],"data_path":"data/detection-rules/243380fa-11eb-4141-af92-e14925e77c1b.json","kind":"sigma"}
