This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious ClickFix/FileFix Execution Pattern
Original Source:
[Sigma source]
Title:
Suspicious ClickFix/FileFix Execution Pattern
Status:
experimental
Description:
Detects suspicious execution patterns where users are tricked into running malicious commands via clipboard manipulation, either through the Windows Run dialog (ClickFix) or File Explorer address bar (FileFix). Attackers leverage social engineering campaigns—such as fake CAPTCHA challenges or urgent alerts—encouraging victims to paste clipboard contents, often executing mshta.exe, powershell.exe, or similar commands to infect systems.
References:
-https://github.com/JohnHammond/recaptcha-phish
-https://www.zscaler.com/blogs/security-research/deepseek-lure-using-captchas-spread-malware
-https://www.threatdown.com/blog/clipboard-hijacker-tries-to-install-a-trojan/
-https://app.any.run/tasks/5c16b4db-4b36-4039-a0ed-9b09abff8be2
-https://www.esentire.com/security-advisories/netsupport-rat-clickfix-distribution
-https://www.scpx.com.au/2025/11/16/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/
Author:
montysecurity, Swachchhanda Shrawan Poudel (Nextron Systems)
Date:
2025-11-19
modified:
None
Tags:
-'attack.execution'
-'attack.t1204.001'
-'attack.t1204.004'
Logsource:
category: process_creation
product: windows
Detection:
selection_parent:
ParentImage|endswith
:
'\explorer.exe'
CommandLine|contains
:
'#'
selection_cli_captcha:
CommandLine|contains
:
-'account'
-'anti-bot'
-'botcheck'
-'captcha'
-'challenge'
-'confirmation'
-'fraud'
-'human'
-'identification'
-'identificator'
-'identity'
-'robot'
-'validation'
-'verification'
-'verify'
condition
:
all of selection_*
Falsepositives:
-Unlikely
Level:
high