Potential Ransomware Activity Using LegalNotice Message

 Original Source: [Sigma source]
Title: Potential Ransomware Activity Using LegalNotice Message
Status: test
Description:Detect changes to the "LegalNoticeCaption" or "LegalNoticeText" registry values where the message set contains keywords often used in ransomware ransom messages
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/5c1e6f1b4fafd01c8d1ece85f510160fc1275fbf/atomics/T1491.001/T1491.001.md
Author: frack113
Date: 2022-12-11
modified:2023-08-17
Tags:
  • -'attack.impact'
  • -'attack.t1491.001'
Logsource:
  • product: windows
  • category: registry_set
Detection:
  selection:
    TargetObject|contains:
      -'\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeCaption'
      -'\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeText'

    Details|contains:
      -'encrypted'
      -'Unlock-Password'
      -'paying'

  condition:selection
Falsepositives:
  -Unknown
Level: high