This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential NetWire RAT Activity - Registry
Original Source:
[Sigma source]
Title:
Potential NetWire RAT Activity - Registry
Status:
test
Description:
Detects registry keys related to NetWire RAT
References:
-https://www.fortinet.com/blog/threat-research/new-netwire-rat-variant-spread-by-phishing
-https://resources.infosecinstitute.com/topic/netwire-malware-what-it-is-how-it-works-and-how-to-prevent-it-malware-spotlight/
-https://unit42.paloaltonetworks.com/guloader-installing-netwire-rat/
-https://blogs.blackberry.com/en/2021/09/threat-thursday-netwire-rat-is-coming-down-the-line
-https://app.any.run/tasks/41ecdbde-4997-4301-a350-0270448b4c8f/
Author:
Christopher Peacock
Date:
2021-10-07
modified:
2023-02-07
Tags:
-'attack.persistence'
-'attack.defense-evasion'
-'attack.t1112'
Logsource:
product: windows
category: registry_add
Detection:
selection:
EventType
:
'CreateKey'
TargetObject|contains
:
'\software\NetWire'
condition
:
selection
Falsepositives:
-Unknown
Level:
high