import "hash" rule bulwark_https_bulwarkblack_com_the_updated_apt_playbook_tales_from_the_kimsuky_threat_actor_grou { meta: author = "Bulwark Black LLC" source = "https://bulwarkblack.com/the-updated-apt-playbook-tales-from-the-kimsuky-threat-actor-group/" description = "Auto-extracted indicators. Verify before use; not a behavioral detection rule." generated = "2026-08-27T00:00:00Z" tlp = "TLP:CLEAR" indicator_count = "14" strings: $s0 = "00701111.000webhostapp.com" ascii wide nocase // Domains $s1 = "gosiclass.com" ascii wide nocase // Domains $s2 = "gosiweb.gosiclass.com" ascii wide nocase // Domains $s3 = "niscarea.com" ascii wide nocase // Domains $s4 = "http://gosiweb.gosiclass.com/m/gnu/convert/html/com/list.php?query=6" ascii wide nocase // URLs condition: any of ($s*) or hash.md5(0, filesize) == "364d4fdf430477222fe854b3cd5b6d40" or hash.md5(0, filesize) == "71db2ae9c36403cec1fd38864d64f239" or hash.md5(0, filesize) == "f35b05779e9538cec363ca37ab38e287" or hash.sha1(0, filesize) == "5c7b2705155023e6e438399d895d30bf924e0547" or hash.sha1(0, filesize) == "b5224224fdbabdea53a91a96e9f816c6f9a8708c" or hash.sha1(0, filesize) == "d4fa57f9c9e35222a8cacddc79055c1d76907fb9" or hash.sha256(0, filesize) == "c62677543eeb50e0def44fc75009a7748cdbedd0a3ccf62f50d7f219f6a5aa05" or hash.sha256(0, filesize) == "da79eea1198a1a10e2ffd50fd949521632d8f252fb1aadb57a45218482b9fd89" or hash.sha256(0, filesize) == "e8000ddfddbe120b5f2fb3677abbad901615d1abd01a0de204fade5d2dd5ad0d" }