Sigma Rule Library

FlowCloud Registry Markers

Detects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.

View on GitHubOpen raw file

Detection logic

selection

TargetObject|contains:
  - \HARDWARE\{2DB80286-1784-48b5-A751-B6ED1F490303}
  - \HARDWARE\{804423C2-F490-4ac3-BFA5-13DEDE63A71A}
  - \HARDWARE\{A5124AF5-DF23-49bf-B0ED-A18ED3DEA027}
  - \SYSTEM\Setup\PrintResponsor\

Condition

selection

Raw YAML

title: FlowCloud Registry Markers
id: 5118765f-6657-4ddb-a487-d7bd673abbf1
status: test
description: |
    Detects FlowCloud malware registry markers from threat group TA410.
    The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.
references:
    - https://www.proofpoint.com/us/blog/threat-insight/ta410-group-behind-lookback-attacks-against-us-utilities-sector-returns-new
author: NVISO
date: 2020-06-09
modified: 2024-03-20
tags:
    - attack.persistence
    - attack.defense-impairment
    - attack.t1112
    - detection.emerging-threats
logsource:
    product: windows
    category: registry_event
detection:
    selection:
        TargetObject|contains:
            - '\HARDWARE\{2DB80286-1784-48b5-A751-B6ED1F490303}'
            - '\HARDWARE\{804423C2-F490-4ac3-BFA5-13DEDE63A71A}'
            - '\HARDWARE\{A5124AF5-DF23-49bf-B0ED-A18ED3DEA027}'
            - '\SYSTEM\Setup\PrintResponsor\'
    condition: selection
falsepositives:
    - Unlikely
level: critical

False positives

  • Unlikely

References

Similar rules