import "hash" rule bulwark_https_bulwarkblack_com_strikeshark_sharkloader_cobalt_strike_defense { meta: author = "Bulwark Black LLC" source = "https://bulwarkblack.com/strikeshark-sharkloader-cobalt-strike-defense/" description = "Auto-extracted indicators. Verify before use; not a behavioral detection rule." generated = "2026-08-27T00:00:00Z" tlp = "TLP:CLEAR" indicator_count = "13" strings: $s0 = "connect-microsoft.com" ascii wide nocase // Domains $s1 = "ms-record.com" ascii wide nocase // Domains $s2 = "ms-record.top" ascii wide nocase // Domains $s3 = "ms-tray.top" ascii wide nocase // Domains condition: any of ($s*) or hash.md5(0, filesize) == "1f65544978b8ea0e745e573b8ee9684b" or hash.md5(0, filesize) == "24fcebdeecba65004fdb0923763d74fd" or hash.md5(0, filesize) == "9c872a0d5d5a38950e8b9ac9b488be3f" or hash.md5(0, filesize) == "9cbd560f820c95d7c38342cd558cb5c6" or hash.md5(0, filesize) == "a514d1bb62d7916475946fe7c07ac0aa" or hash.md5(0, filesize) == "aa3086be652c8b20b0b29b2730d57119" or hash.md5(0, filesize) == "b3352b42432dedc4a519f011dc8b5d5a" or hash.md5(0, filesize) == "c559cc68986933200fd5d9e4388e2f58" or hash.md5(0, filesize) == "d98f568496512e4f98670c61c97cb07a" }