Suspicious Registry Keys
Description
ZLoader was delivered in a campaign in late summer 2021 using malvertising to download malicious .msi files onto affected machines. This campaign was originally tweeted by @MsftSecIntel on Twitter. In this campaign, the malicious .msi files create registry keys that use that attacker-created comapny names.
Query · kql
DeviceRegistryEvents
| where RegistryValueData in('Flyintellect Inc.', 'Datalyst ou')