import "hash" rule bulwark_https_bulwarkblack_com_zimbra_cve_2026_73570_mail_server_incident_review { meta: author = "Bulwark Black LLC" source = "https://bulwarkblack.com/zimbra-cve-2026-73570-mail-server-incident-review/" description = "Auto-extracted indicators. Verify before use; not a behavioral detection rule." generated = "2026-09-30T15:03:54Z" tlp = "TLP:CLEAR" indicator_count = "21" strings: $s0 = "aka.ms" ascii wide nocase // Domains $s1 = "bypass.eu.org" ascii wide nocase // Domains $s2 = "dnslog.pp.ua" ascii wide nocase // Domains $s3 = "mexico-cashpay-test.s3.dualstack.mx-central-1.amazonaws.com" ascii wide nocase // Domains $s4 = "oast.fun" ascii wide nocase // Domains $s5 = "oast.online" ascii wide nocase // Domains $s6 = "psk1zim.abrdns.com" ascii wide nocase // Domains $s7 = "requestrepo.com" ascii wide nocase // Domains $s8 = "tls.psk1zim.abrdns.com" ascii wide nocase // Domains $s9 = "transzimbra.linkpc.net" ascii wide nocase // Domains $s10 = "wslogzimbra.linkpc.net" ascii wide nocase // Domains $s11 = "wsweb03.blob.core.windows.net" ascii wide nocase // Domains $s12 = "https://aka.ms/downloadazcopy-v10-linux" ascii wide nocase // URLs condition: any of ($s*) or hash.sha256(0, filesize) == "22ef852f6ebc39ee71235b90648b4b200b385c47d25c79545986493f8c70db69" or hash.sha256(0, filesize) == "518fe65dd349180191d9b258ab24876aaed6613cd657d0b626d1fc24e03a22b6" or hash.sha256(0, filesize) == "65a7576c389326b6cdf9c993d0be6e5d50fed9655d1cdf2a3a50f2c21c8ec435" or hash.sha256(0, filesize) == "6ab7de2509038edf580aef6229c1c3db17f4da8f2d7d940818faf617d1938244" or hash.sha256(0, filesize) == "aea991f694911e321b0ab97534f2ad0291c392c0a43dabff664c563618bd036d" or hash.sha256(0, filesize) == "b594a42b8f1c6f090327bb9a3361c2d3515537fb7ac8da6b9061b9a3f330e159" or hash.sha256(0, filesize) == "bf28f38122bf20d5fac969cc414daa6a890cdea872d389ca93d2092b6b7773cf" or hash.sha256(0, filesize) == "dee5af1c0f76b45d28bafd6e60c07bb8e391d98addf81ef8f13d073acdb3c48a" }