Potential Qakbot Registry Activity

Rule Info

Name
Potential Qakbot Registry Activity
Author
Hieu Tran
Description
Detects a registry key used by IceID in a campaign that distributes malicious OneNote files
Date
2023-03-13 00:00:00
Modified
None
Id
1c8e96cd-2bed-487d-9de0-b46c90cade56
Tags
attack.defense-evasion attack.t1112
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
github-actions[bot]
Merge PR #4700 from @nasbench - Promote older rules status from `experimental` to `test`
2024-02-01
Nasreddine Bencherchali
Merge PR #4482 From @nasbench - Add New Automation Workflows
2023-10-18
Hieu Tran
feat: new rules related to ZScaler blog - OneNote: A Growing Threat for Malware Distribution (#4111)
2023-03-17