Detection rules › Sigma
FlowCloud Registry Markers
Detects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.
Known false positives
- Unlikely
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Persistence | |
| Defense Impairment |
Telemetry coverage
Rule body
title: FlowCloud Registry Markers
id: 5118765f-6657-4ddb-a487-d7bd673abbf1
status: test
description: |
Detects FlowCloud malware registry markers from threat group TA410.
The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.
references:
- https://www.proofpoint.com/us/blog/threat-insight/ta410-group-behind-lookback-attacks-against-us-utilities-sector-returns-new
author: NVISO
date: 2020-06-09
modified: 2024-03-20
tags:
- attack.persistence
- attack.defense-impairment
- attack.t1112
- detection.emerging-threats
logsource:
product: windows
category: registry_event
detection:
selection:
TargetObject|contains:
- '\HARDWARE\{2DB80286-1784-48b5-A751-B6ED1F490303}'
- '\HARDWARE\{804423C2-F490-4ac3-BFA5-13DEDE63A71A}'
- '\HARDWARE\{A5124AF5-DF23-49bf-B0ED-A18ED3DEA027}'
- '\SYSTEM\Setup\PrintResponsor\'
condition: selection
falsepositives:
- Unlikely
level: critical
Stages and Predicates
Stage 0: condition
selectionStage 1: selection
selection:
TargetObject|contains:
- '\HARDWARE\{2DB80286-1784-48b5-A751-B6ED1F490303}'
- '\HARDWARE\{804423C2-F490-4ac3-BFA5-13DEDE63A71A}'
- '\HARDWARE\{A5124AF5-DF23-49bf-B0ED-A18ED3DEA027}'
- '\SYSTEM\Setup\PrintResponsor\'
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
TargetObject | match |
| field:"TargetObject" kind:match |