Potential NetWire RAT Activity - Registry

 Original Source: [Sigma source]
Title: Potential NetWire RAT Activity - Registry
Status: test
Description:Detects registry keys related to NetWire RAT
References:
  -https://www.fortinet.com/blog/threat-research/new-netwire-rat-variant-spread-by-phishing
  -https://resources.infosecinstitute.com/topic/netwire-malware-what-it-is-how-it-works-and-how-to-prevent-it-malware-spotlight/
  -https://unit42.paloaltonetworks.com/guloader-installing-netwire-rat/
  -https://blogs.blackberry.com/en/2021/09/threat-thursday-netwire-rat-is-coming-down-the-line
  -https://app.any.run/tasks/41ecdbde-4997-4301-a350-0270448b4c8f/
Author: Christopher Peacock
Date: 2021-10-07
modified:2023-02-07
Tags:
  • -'attack.persistence'
  • -'attack.defense-evasion'
  • -'attack.t1112'
Logsource:
  • product: windows
  • category: registry_add
Detection:
  selection:
    EventType: 'CreateKey'
    TargetObject|contains: '\software\NetWire'
  condition:selection
Falsepositives:
  -Unknown
Level: high