Potential Qakbot Registry Activity

 Original Source: [Sigma source]
Title: Potential Qakbot Registry Activity
Status: test
Description:Detects a registry key used by IceID in a campaign that distributes malicious OneNote files
References:
  -https://www.zscaler.com/blogs/security-research/onenote-growing-threat-malware-distribution
Author: Hieu Tran
Date: 2023-03-13
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1112'
Logsource:
  • category: registry_event
  • product: windows
Detection:
  selection:
    TargetObject|endswith: '\Software\firm\soft\Name'
  condition:selection
Falsepositives:
  -Unknown
Level: high