Potential KamiKakaBot Activity - Lure Document Execution

Rule Info

Name
Potential KamiKakaBot Activity - Lure Document Execution
Author
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)
Description
Detects the execution of a Word document via the WinWord Start Menu shortcut. This behavior was observed being used by KamiKakaBot samples in order to initiate the 2nd stage of the infection.
Date
2024-03-22 00:00:00
Modified
None
Id
24474469-bd80-46cc-9e08-9fbe81bfaaca
Tags
attack.execution attack.t1059 detection.emerging-threats
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
Nasreddine Bencherchali
Merge PR #4781 from @nasbench - KamiKakaBot Malware Related Rules
2024-03-25