Potential KamiKakaBot Activity - Shutdown Schedule Task Creation

Rule Info

Name
Potential KamiKakaBot Activity - Shutdown Schedule Task Creation
Author
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)
Description
Detects the creation of a schedule task that runs weekly and execute the "shutdown /l /f" command. This behavior was observed being used by KamiKakaBot samples in order to achieve persistence on a system.
Date
2024-03-22 00:00:00
Modified
None
Id
fe9e8ba9-4419-41e6-a574-bd9f7b3af961
Tags
attack.persistence detection.emerging-threats DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
Nasreddine Bencherchali
Merge PR #4781 from @nasbench - KamiKakaBot Malware Related Rules
2024-03-25