FlowCloud Registry Markers
Description
Detects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.
Query · sigma
selection:
TargetObject|contains:
- \HARDWARE\{2DB80286-1784-48b5-A751-B6ED1F490303}
- \HARDWARE\{804423C2-F490-4ac3-BFA5-13DEDE63A71A}
- \HARDWARE\{A5124AF5-DF23-49bf-B0ED-A18ED3DEA027}
- \SYSTEM\Setup\PrintResponsor\
condition: selection
Known false positives
- Unlikely