FlowCloud Registry Markers
Detects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.
Detection logic
selection
TargetObject|contains:
- \HARDWARE\{2DB80286-1784-48b5-A751-B6ED1F490303}
- \HARDWARE\{804423C2-F490-4ac3-BFA5-13DEDE63A71A}
- \HARDWARE\{A5124AF5-DF23-49bf-B0ED-A18ED3DEA027}
- \SYSTEM\Setup\PrintResponsor\Condition
selectionRaw YAML
title: FlowCloud Registry Markers
id: 5118765f-6657-4ddb-a487-d7bd673abbf1
status: test
description: |
Detects FlowCloud malware registry markers from threat group TA410.
The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.
references:
- https://www.proofpoint.com/us/blog/threat-insight/ta410-group-behind-lookback-attacks-against-us-utilities-sector-returns-new
author: NVISO
date: 2020-06-09
modified: 2024-03-20
tags:
- attack.persistence
- attack.defense-impairment
- attack.t1112
- detection.emerging-threats
logsource:
product: windows
category: registry_event
detection:
selection:
TargetObject|contains:
- '\HARDWARE\{2DB80286-1784-48b5-A751-B6ED1F490303}'
- '\HARDWARE\{804423C2-F490-4ac3-BFA5-13DEDE63A71A}'
- '\HARDWARE\{A5124AF5-DF23-49bf-B0ED-A18ED3DEA027}'
- '\SYSTEM\Setup\PrintResponsor\'
condition: selection
falsepositives:
- Unlikely
level: criticalFalse positives
- Unlikely