Rule Info
Name
Potential KamiKakaBot Activity - Lure Document Execution
Author
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)
Description
Detects the execution of a Word document via the WinWord Start Menu shortcut.
This behavior was observed being used by KamiKakaBot samples in order to initiate the 2nd stage of the infection.
Date
2024-03-22 00:00:00
Modified
None
Id
24474469-bd80-46cc-9e08-9fbe81bfaaca
Tags
attack.execution attack.t1059 detection.emerging-threats
Type
Community Rule
Link to Public Repo