title: FlowCloud Registry Markers id: 5118765f-6657-4ddb-a487-d7bd673abbf1 status: test description: | Detects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components. references: - https://www.proofpoint.com/us/blog/threat-insight/ta410-group-behind-lookback-attacks-against-us-utilities-sector-returns-new author: NVISO date: 2020-06-09 modified: 2024-03-20 tags: - attack.persistence - attack.defense-impairment - attack.t1112 - detection.emerging-threats logsource: product: windows category: registry_event detection: selection: TargetObject|contains: - '\HARDWARE\{2DB80286-1784-48b5-A751-B6ED1F490303}' - '\HARDWARE\{804423C2-F490-4ac3-BFA5-13DEDE63A71A}' - '\HARDWARE\{A5124AF5-DF23-49bf-B0ED-A18ED3DEA027}' - '\SYSTEM\Setup\PrintResponsor\' condition: selection falsepositives: - Unlikely level: critical