/*
 * Bulwark Black - YARA rules auto-generated from published cyber threat reporting.
 * 194 rules across 194 reports: network-indicator strings
 * (domains, URLs, IPs) and known file hashes (MD5/SHA-1/SHA-256), grouped by report.
 * Home: https://bulwarkblack.com/feeds/   Regenerated on every new report.
 * Generated: 2026-08-04
 *
 * Auto-extracted from third-party reporting. TUNE AND VERIFY before deploying:
 * a matching indicator string does not by itself prove a file is malicious.
 */

import "hash"

rule BulwarkBlack_langflow_validate_code_rce_ai_workflow_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Langflow RCE Shows Why AI Workflow Tools Need Cloud-Grade Isolation"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/langflow-validate-code-rce-ai-workflow-defense/"
        date = "2026-08-04"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "alias.name" ascii wide nocase
        $n1 = "com.apple.sharepoint.group" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_bindcloak_backdoor_c2_detection_government_intrusion_defense
{
    meta:
        description = "Indicators from Bulwark Black report: BINDCLOAK Shows Why C2 Detection Needs Message-Level Visibility"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/bindcloak-backdoor-c2-detection-government-intrusion-defense/"
        date = "2026-08-03"
        net_indicators = 9
        file_hashes = 28
    strings:
        $n0 = "api.telegram.org" ascii wide nocase
        $n1 = "cert.hypersnet.com" ascii wide nocase
        $n2 = "contacts.ftabnews.com" ascii wide nocase
        $n3 = "message.chat.id" ascii wide nocase
        $n4 = "ssl.blsouqs.com" ascii wide nocase
        $n5 = "blsouqs.com" ascii wide nocase
        $n6 = "ftabnews.com" ascii wide nocase
        $n7 = "https://api.telegram.org/bot[BOT_TOKEN]/getUpdates?offset=[N" ascii wide nocase
        $n8 = "hypersnet.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "087499849115eb28c4364581d2b28d09" or
        hash.md5(0, filesize) == "28b47bdf16d7af6f8ec21218eac9145a" or
        hash.md5(0, filesize) == "3f60d53a2b5737d77e058d9e33cbe9eb" or
        hash.md5(0, filesize) == "68926e6c958562deaae35de3d9f59de3" or
        hash.md5(0, filesize) == "78a4f8574830bf7fbaf63d7da09be2b8" or
        hash.md5(0, filesize) == "7a14a99d70d42d3f7bf72f843185fc07" or
        hash.md5(0, filesize) == "7cbc51ada1a4aec88660ec32c408114b" or
        hash.md5(0, filesize) == "97124a93766be732e8fef5a56a5346a2" or
        hash.md5(0, filesize) == "b776eb638fbb535708fb92b12fcc1731" or
        hash.md5(0, filesize) == "c99f29ac08454855b3d538960bb2f34f" or
        hash.sha1(0, filesize) == "1099bf51e53bd5fb32401edb4e0be841d8486b19" or
        hash.sha1(0, filesize) == "2377c47cfde148c2140faa7105628174f9c4d56d" or
        hash.sha1(0, filesize) == "577b1cc894636f4ac5ad670b0079b9b7ade137c3" or
        hash.sha1(0, filesize) == "86ee99f293a30720bcc898a4a8e391f93fb9be95" or
        hash.sha1(0, filesize) == "c1f16e31ae71372ee45fa6fd6927c7b887a4e3f2" or
        hash.sha1(0, filesize) == "ccb2002fe8f5cc1f511d52309625b52d1c507421" or
        hash.sha1(0, filesize) == "ee287d6a09295502ab2407aec336f9f0d8477d68" or
        hash.sha1(0, filesize) == "f46c01a5be2e08e36d4ec3302a8650a6ed25ec14" or
        hash.sha1(0, filesize) == "fee6806c96f87bf1e240a2eb6fd7e045101d58d3" or
        hash.sha256(0, filesize) == "0637069c7052118fd5c0f1113541bdd35e5f71cd9689f2516045da152c6fa8d9" or
        hash.sha256(0, filesize) == "32529043d15e9111ba284f1d8a9e4b3f58e071c6b69c8f271d4d02feacd44e66" or
        hash.sha256(0, filesize) == "3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d" or
        hash.sha256(0, filesize) == "3b3eaea783fd6dab90f0408274bf8a9c49adbdc70c0efd70658d65b0e1684a3f" or
        hash.sha256(0, filesize) == "5c2fe953da53da66fbcbb3be0fd6b63907c10714c337f287b2fc258857bbff6d" or
        hash.sha256(0, filesize) == "789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bd" or
        hash.sha256(0, filesize) == "c84542ac30cbe9bb8bd648bad323c37801023bf9451c1c0990452466e084340f" or
        hash.sha256(0, filesize) == "cac1f37beaa814461f7709a073aeec468c74e5d70f7d693a9e367ece4a3a78be" or
        hash.sha256(0, filesize) == "db11ff3f37a8b2aa25c480871504b886a6364167ecb501eacf7345f6bbf9582b"
}

rule BulwarkBlack_dprk_npm_compromises_dependency_trust_identity_risk
{
    meta:
        description = "Indicators from Bulwark Black report: DPRK npm Compromises Show Why Dependency Trust Is Now Identity Risk"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/dprk-npm-compromises-dependency-trust-identity-risk/"
        date = "2026-08-03"
        net_indicators = 2
        file_hashes = 2
    strings:
        $n0 = "216.74.123.126" ascii wide
        $n1 = "npmjs.store" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "2014d09c7ded74d89c885b5f11693865224116f1b25df9330e61fe528f419d73" or
        hash.sha256(0, filesize) == "24604384b0e748ada07923630b3d037489e696284a98c4409fb9b6763565571f"
}

rule BulwarkBlack_nable_ncentral_active_exploitation_msp_control_plane_defense
{
    meta:
        description = "Indicators from Bulwark Black report: N-able N-central Exploitation Shows Why MSP Tools Are Control-Plane Risk"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/nable-ncentral-active-exploitation-msp-control-plane-defense/"
        date = "2026-08-02"
        net_indicators = 6
        file_hashes = 0
    strings:
        $n0 = "173.249.252.200" ascii wide
        $n1 = "37.19.210.32" ascii wide
        $n2 = "68.235.46.214" ascii wide
        $n3 = "87.249.138.34" ascii wide
        $n4 = "www.cve.org" ascii wide nocase
        $n5 = "https://www.cve.org/CVERecord?id=CVE-2026-18556" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_hollowgraph_microsoft_365_calendar_c2_defense
{
    meta:
        description = "Indicators from Bulwark Black report: HOLLOWGRAPH Shows Why Microsoft 365 Is Now Part of the C2 Battlefield"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/hollowgraph-microsoft-365-calendar-c2-defense/"
        date = "2026-08-02"
        net_indicators = 8
        file_hashes = 0
    strings:
        $n0 = "Booking.com" ascii wide nocase
        $n1 = "BugsBounty.com" ascii wide nocase
        $n2 = "Builder.ai" ascii wide nocase
        $n3 = "Coinopsy.com" ascii wide nocase
        $n4 = "Collectibles.com" ascii wide nocase
        $n5 = "Discord.io" ascii wide nocase
        $n6 = "Duck.ai" ascii wide nocase
        $n7 = "cloudlanecdn.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_fuyao_android_tv_botnet_ad_fraud_business_network_risk
{
    meta:
        description = "Indicators from Bulwark Black report: Fuyao Android TV Botnet Shows Why Cheap Streaming Sticks Are Business Network Risk"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/fuyao-android-tv-botnet-ad-fraud-business-network-risk/"
        date = "2026-08-02"
        net_indicators = 3
        file_hashes = 1
    strings:
        $n0 = "fwgcloud.com" ascii wide nocase
        $n1 = "min.news" ascii wide nocase
        $n2 = "https://min.news/en/economy/dd0c59854fc23ac7c8d9b4fad57e3360.html" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "dd0c59854fc23ac7c8d9b4fad57e3360"
}

rule BulwarkBlack_sonicwall_sma_inc_ransomware_exploit_chain_defense
{
    meta:
        description = "Indicators from Bulwark Black report: SonicWall SMA Exploit Chain Shows Why VPN Appliances Need Incident Response, Not Just Patching"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/sonicwall-sma-inc-ransomware-exploit-chain-defense/"
        date = "2026-08-01"
        net_indicators = 27
        file_hashes = 12
    strings:
        $n0 = "108.205.8.173" ascii wide
        $n1 = "147.45.51.19" ascii wide
        $n2 = "149.0.0.1" ascii wide
        $n3 = "150.241.210.53" ascii wide
        $n4 = "173.239.211.0" ascii wide
        $n5 = "193.37.32.179" ascii wide
        $n6 = "193.37.32.214" ascii wide
        $n7 = "202.8.105.201" ascii wide
        $n8 = "216.73.163.151" ascii wide
        $n9 = "216.73.163.158" ascii wide
        $n10 = "217.77.15.99" ascii wide
        $n11 = "42.200.172.14" ascii wide
        $n12 = "45.131.194.0" ascii wide
        $n13 = "45.146.54.0" ascii wide
        $n14 = "63.135.161.0" ascii wide
        $n15 = "81.19.140.217" ascii wide
        $n16 = "89.117.20.1" ascii wide
        $n17 = "173.239.211.0/24" ascii wide
        $n18 = "45.131.194.0/24" ascii wide
        $n19 = "45.146.54.0/24" ascii wide
        $n20 = "63.135.161.0/24" ascii wide
        $n21 = "icann.org" ascii wide nocase
        $n22 = "whois.ordertld.com" ascii wide nocase
        $n23 = "www.ordertld.com" ascii wide nocase
        $n24 = "HELPRANS.COM" ascii wide nocase
        $n25 = "http://www.ordertld.com" ascii wide nocase
        $n26 = "https://icann.org/epp#clientTransferProhibited" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "54d21399b8b52b48a0fef68450593e45" or
        hash.md5(0, filesize) == "5cb00bbfe818ee3e85fb99ab1db1af7c" or
        hash.md5(0, filesize) == "5f3a55201c511c9ff9be4c16c41028a2" or
        hash.md5(0, filesize) == "b6df166291f80ee89032d769c99714f3" or
        hash.sha1(0, filesize) == "04d4a9fbb32e967200eb98be014ca914a03bfa6b" or
        hash.sha1(0, filesize) == "5e5b716f2385c818ec61198be1a2a07a4560eac5" or
        hash.sha1(0, filesize) == "b4ee1f50fbb49f0ff5fde3d026343bc23ee08d51" or
        hash.sha1(0, filesize) == "c2b0ae0a1f42a139abe4dd612676066ec1426394" or
        hash.sha256(0, filesize) == "1e1e68bbb899450a57274a8b12082ed4e2040a2aae77014f20431689d2b4edee" or
        hash.sha256(0, filesize) == "81a9af3846bad3a1107164ff7cf0a08e020b31a3b32fd17866e17d4c1565f7f2" or
        hash.sha256(0, filesize) == "8c470301dcb7278f73e622f1950073567b34011c64b60cdfbb0f89803923a5a3" or
        hash.sha256(0, filesize) == "ea9154e374e4f77bc2cf54282e23543573980342a85bc888cb23f20b8bbba081"
}

rule BulwarkBlack_adform_script_compromise_third_party_tag_supply_chain_controls
{
    meta:
        description = "Indicators from Bulwark Black report: Adform Script Compromise Shows Why Third-Party Tags Need Supply-Chain Controls"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/adform-script-compromise-third-party-tag-supply-chain-controls/"
        date = "2026-08-01"
        net_indicators = 6
        file_hashes = 1
    strings:
        $n0 = "84.32.102.230" ascii wide
        $n1 = "pastebin.com" ascii wide nocase
        $n2 = "s2.adform.net" ascii wide nocase
        $n3 = "http://84.32.102.230:7744/p?h=example.com&amp;u=/test" ascii wide nocase
        $n4 = "https://pastebin.com/mc7psaNF" ascii wide nocase
        $n5 = "https://s2.adform.net/banners/scripts/st/trackpoint-async.js" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "02ff86c7f9fe609a753ff15bda90baa3c3e0d4a2e559ec4fcf8a3de0954b7c55"
}

rule BulwarkBlack_captivecrunch_travel_wifi_identity_attack_surface
{
    meta:
        description = "Indicators from Bulwark Black report: CaptiveCrunch Shows Why Travel Wi-Fi Is Now an Identity Attack Surface"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/captivecrunch-travel-wifi-identity-attack-surface/"
        date = "2026-08-01"
        net_indicators = 24
        file_hashes = 2
    strings:
        $n0 = "104.194.159.150" ascii wide
        $n1 = "107.189.26.194" ascii wide
        $n2 = "213.145.86.112" ascii wide
        $n3 = "31.57.243.154" ascii wide
        $n4 = "38.146.28.132" ascii wide
        $n5 = "38.146.28.75" ascii wide
        $n6 = "cloudflarecp.com" ascii wide nocase
        $n7 = "cloudflareok.com" ascii wide nocase
        $n8 = "cloudflareportal.com" ascii wide nocase
        $n9 = "connectivity.cloudflareclient.com" ascii wide nocase
        $n10 = "detectportal.brave-http-only.com" ascii wide nocase
        $n11 = "detectportal.firefox.com" ascii wide nocase
        $n12 = "m365-owa.com" ascii wide nocase
        $n13 = "ms365-device.com" ascii wide nocase
        $n14 = "ms365-live.com" ascii wide nocase
        $n15 = "msftconnecttest.com" ascii wide nocase
        $n16 = "msftncsi.com" ascii wide nocase
        $n17 = "nmcheck.gnome.org" ascii wide nocase
        $n18 = "owa-ms365.com" ascii wide nocase
        $n19 = "www.volexity.com" ascii wide nocase
        $n20 = "https://213.145.86.112/cdn/chunks/polyfill-7e2b.min.js" ascii wide nocase
        $n21 = "https://213.145.86.112/t/event" ascii wide nocase
        $n22 = "https://213.145.86.112/t/pixel.gif" ascii wide nocase
        $n23 = "https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593" or
        hash.sha256(0, filesize) == "be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c"
}

rule BulwarkBlack_xcsset_v40_xcode_developer_mac_supply_chain_defense
{
    meta:
        description = "Indicators from Bulwark Black report: XCSSET v40 Shows Why Developer Macs Are Supply-Chain Infrastructure"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/xcsset-v40-xcode-developer-mac-supply-chain-defense/"
        date = "2026-07-31"
        net_indicators = 85
        file_hashes = 1
    strings:
        $n0 = "151.243.109.188" ascii wide
        $n1 = "178.208.92.129" ascii wide
        $n2 = "178.208.92.168" ascii wide
        $n3 = "91.108.106.229" ascii wide
        $n4 = "95.142.35.206" ascii wide
        $n5 = "95.142.35.34" ascii wide
        $n6 = "95.142.37.159" ascii wide
        $n7 = "Settings.app" ascii wide nocase
        $n8 = "Telegram.app" ascii wide nocase
        $n9 = "accapple.ru" ascii wide nocase
        $n10 = "adschecks.ru" ascii wide nocase
        $n11 = "adsmobi.ru" ascii wide nocase
        $n12 = "adsmorein.in" ascii wide nocase
        $n13 = "adsmoreme.in" ascii wide nocase
        $n14 = "amdcdn.ru" ascii wide nocase
        $n15 = "amzndev.in" ascii wide nocase
        $n16 = "amzndev.ru" ascii wide nocase
        $n17 = "amznprod.in" ascii wide nocase
        $n18 = "applecdn.ru" ascii wide nocase
        $n19 = "appledisk.ru" ascii wide nocase
        $n20 = "appledns.ru" ascii wide nocase
        $n21 = "applehosts.ru" ascii wide nocase
        $n22 = "appletime.in" ascii wide nocase
        $n23 = "bulksec.ru" ascii wide nocase
        $n24 = "cdnamz.in" ascii wide nocase
        $n25 = "cdnamz.ru" ascii wide nocase
        $n26 = "cdnapple.in" ascii wide nocase
        $n27 = "cdnatapple.ru" ascii wide nocase
        $n28 = "cdnroute.ru" ascii wide nocase
        $n29 = "checkcdn.ru" ascii wide nocase
        $n30 = "chromeads.ru" ascii wide nocase
        $n31 = "cnmag.ru" ascii wide nocase
        $n32 = "devnetaps.ru" ascii wide nocase
        $n33 = "dnsapple.ru" ascii wide nocase
        $n34 = "dnsrelays.ru" ascii wide nocase
        $n35 = "explorecdn.ru" ascii wide nocase
        $n36 = "fiddlejoy.ru" ascii wide nocase
        $n37 = "figmacat.ru" ascii wide nocase
        $n38 = "figmanets.in" ascii wide nocase
        $n39 = "funchats.ru" ascii wide nocase
        $n40 = "gironetcdn.ru" ascii wide nocase
        $n41 = "goalmate.ru" ascii wide nocase
        $n42 = "googlenets.ru" ascii wide nocase
        $n43 = "greencn.ru" ascii wide nocase
        $n44 = "icloudsnet.ru" ascii wide nocase
        $n45 = "imails.ru" ascii wide nocase
        $n46 = "legalads.in" ascii wide nocase
        $n47 = "littleads.in" ascii wide nocase
        $n48 = "littledns.ru" ascii wide nocase
        $n49 = "maganet.ru" ascii wide nocase
        $n50 = "mindelgate.ru" ascii wide nocase
        $n51 = "netapsdev.ru" ascii wide nocase
        $n52 = "netcdnads.in" ascii wide nocase
        $n53 = "netcdnamz.ru" ascii wide nocase
        $n54 = "netcdndev.in" ascii wide nocase
        $n55 = "netcorps.ru" ascii wide nocase
        $n56 = "netsprot.in" ascii wide nocase
        $n57 = "netsproto.in" ascii wide nocase
        $n58 = "networkads.in" ascii wide nocase
        $n59 = "p.app" ascii wide nocase
        $n60 = "rigacdn.in" ascii wide nocase
        $n61 = "rigmajoys.in" ascii wide nocase
        $n62 = "rigmanet.ru" ascii wide nocase
        $n63 = "rigmanets.in" ascii wide nocase
        $n64 = "sahusuzuki.in" ascii wide nocase
        $n65 = "stuffdns.in" ascii wide nocase
        $n66 = "testjoys.ru" ascii wide nocase
        $n67 = "timewebnet.in" ascii wide nocase
        $n68 = "vigmanet.ru" ascii wide nocase
        $n69 = "whitead.in" ascii wide nocase
        $n70 = "whiteads.ru" ascii wide nocase
        $n71 = "wincdn.ru" ascii wide nocase
        $n72 = "windsecure.ru" ascii wide nocase
        $n73 = "amzndev.in/d/zw_sfp64" ascii wide nocase
        $n74 = "amzndev.ru/d/zw_sfp64" ascii wide nocase
        $n75 = "googlenets.ru/d/zw_sfp64" ascii wide nocase
        $n76 = "https://amzndev.in/d/zw_sfp64" ascii wide nocase
        $n77 = "https://amzndev.ru/d/zw_sfp64" ascii wide nocase
        $n78 = "https://googlenets.ru/d/zw_sfp64" ascii wide nocase
        $n79 = "https://netcdndev.in/d/zw_sfp64" ascii wide nocase
        $n80 = "https://whitead.in/d/zw_sfp64" ascii wide nocase
        $n81 = "https://whiteads.ru/d/zw_sfp64" ascii wide nocase
        $n82 = "netcdndev.in/d/zw_sfp64" ascii wide nocase
        $n83 = "whitead.in/d/zw_sfp64" ascii wide nocase
        $n84 = "whiteads.ru/d/zw_sfp64" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha1(0, filesize) == "6e480d648fa1b70612f5d198a66875e28847547d"
}

rule BulwarkBlack_4g_5g_core_flaws_telecom_zero_trust
{
    meta:
        description = "Indicators from Bulwark Black report: 84 4G/5G Core Flaws Show Why Telecom Trust Zones Need Zero Trust"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/4g-5g-core-flaws-telecom-zero-trust/"
        date = "2026-07-31"
        net_indicators = 3
        file_hashes = 0
    strings:
        $n0 = "doi.org" ascii wide nocase
        $n1 = "scite.ai" ascii wide nocase
        $n2 = "https://doi.org/10.48550/arXiv.2607.10315" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_astaroth_whatsapp_web_spambot_browser_session_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Astaroth WhatsApp Web Spambot Shows Browser Sessions Are Distribution Infrastructure"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/astaroth-whatsapp-web-spambot-browser-session-defense/"
        date = "2026-07-31"
        net_indicators = 12
        file_hashes = 5
    strings:
        $n0 = "developer.chrome.com" ascii wide nocase
        $n1 = "docsmoonstudioclayworks.online" ascii wide nocase
        $n2 = "g.us" ascii wide nocase
        $n3 = "impostosrapido.top" ascii wide nocase
        $n4 = "plansonval.impostosrapido.top" ascii wide nocase
        $n5 = "varegjopeaks.com" ascii wide nocase
        $n6 = "developer.chrome.com/docs/chromedriver/capabilities" ascii wide nocase
        $n7 = "docsmoonstudioclayworks.online/arquivoatualizado/gera.php" ascii wide nocase
        $n8 = "https://developer.chrome.com/docs/chromedriver/capabilities" ascii wide nocase
        $n9 = "https://docsmoonstudioclayworks.online/arquivoatualizado/gera.php" ascii wide nocase
        $n10 = "https://varegjopeaks.com/api/" ascii wide nocase
        $n11 = "varegjopeaks.com/api/" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "6168d63fad22a4e5e45547ca6116ef68bb5173e17e25fd1714f7cc1e4f7b41e1" or
        hash.sha256(0, filesize) == "a1aa786e02fb9a37a71e0f76b052ab284ba877f2aaa2fb28f05d60487389976a" or
        hash.sha256(0, filesize) == "c7c62303ee1a37fd7a6e2db9c590ba75c647bc4d22d7dca50cfa8879222ac9e1" or
        hash.sha256(0, filesize) == "d89105c4d567a95f674ed6eac538e32e288b658a4222a3d52e284a77782af4d5" or
        hash.sha256(0, filesize) == "ec43a17685e3a555c2eb5f0a2802e9e45d5a2a5d49a0803155acbd74d9ecdbd7"
}

rule BulwarkBlack_ta488_outlook_web_access_owareaper_half_click_exploit
{
    meta:
        description = "Indicators from Bulwark Black report: TA488 Turns Outlook Web Access Into a Stealthy Persistence Layer"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/ta488-outlook-web-access-owareaper-half-click-exploit/"
        date = "2026-07-31"
        net_indicators = 8
        file_hashes = 1
    strings:
        $n0 = "Weserv.nl" ascii wide nocase
        $n1 = "acocdn.com" ascii wide nocase
        $n2 = "asecdns.com" ascii wide nocase
        $n3 = "dnsrecursive.eu" ascii wide nocase
        $n4 = "i3.wp.com" ascii wide nocase
        $n5 = "images.weserv.nl" ascii wide nocase
        $n6 = "slack-imgs.com" ascii wide nocase
        $n7 = "tdndns.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4"
}

rule BulwarkBlack_open_source_supply_chain_build_pipeline_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Open Source Supply Chain Compromise Needs Build-Pipeline Defense, Not Just Dependency Scanning"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/open-source-supply-chain-build-pipeline-defense/"
        date = "2026-07-30"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "OSV.dev" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_autonomous_ai_agent_espionage_finance_ministry_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Autonomous AI Agent Espionage Shows Why Post-Compromise Speed Matters"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/autonomous-ai-agent-espionage-finance-ministry-defense/"
        date = "2026-07-30"
        net_indicators = 11
        file_hashes = 12
    strings:
        $n0 = "103.97.0.57" ascii wide
        $n1 = "118.107.222.232" ascii wide
        $n2 = "131.0.0.0" ascii wide
        $n3 = "202.181.27.115" ascii wide
        $n4 = "43.246.208.207" ascii wide
        $n5 = "Hunt.io" ascii wide nocase
        $n6 = "cdn.jsdelivr.net" ascii wide nocase
        $n7 = "java.io" ascii wide nocase
        $n8 = "mail4.pl" ascii wide nocase
        $n9 = "redhatupdating432.dnsrd.com" ascii wide nocase
        $n10 = "dnsrd.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "0f8c905aa25c86f85454acb7e77bf5c50220c2a82e5b69a33741e55c8a85f2fc" or
        hash.sha256(0, filesize) == "2a4cb412efa93fed7c3b3b3e49d6247b11a95ce9fddf71d9fe9db8e5f0068e0d" or
        hash.sha256(0, filesize) == "5633bc0033fde3aad929d6cbd47c554e264180360b017aae04687c2d6d83f753" or
        hash.sha256(0, filesize) == "576c70e12be8b2e8e7c35a5feb082e90621989adce8e64400126918d37f13e49" or
        hash.sha256(0, filesize) == "58338a93fee4e008ea28e459c4d1598313d1524763ab13894ab63bf2bec4302a" or
        hash.sha256(0, filesize) == "9ff4b6d3b7dbb023bad65d2538ade745d46b763e5a12116c9c83aa2f6f5d96aa" or
        hash.sha256(0, filesize) == "dbbb8a11a239da11cbaf99f847a2d032f34d3b522e13b0fd4ef7b2649da7123b" or
        hash.sha256(0, filesize) == "ff662b60f6a142f99292fbdd65dd1ccd79dc9628686ddf5935c92f7fb1b62a81" or
        hash.sha256(0, filesize) == "a9447ae174f4aa54f760b7d7cc985c1a970f31e151d3ff66fac247f99ba1b509" or
        hash.sha256(0, filesize) == "b65b7ede835ebba36294d52d7780065523340ee09bb8b209ef2dc495e53dfd53" or
        hash.sha256(0, filesize) == "d252ee7b348b7e43e432d8fb154465838f5cd5fb564905323460e6f0a0c7d1e2" or
        hash.sha256(0, filesize) == "ec7e9ab43a0cc65d29f0b84a93ba88c43d01fed3dec5c968525dc73c03cbfda2"
}

rule BulwarkBlack_fake_payment_sdk_npm_pypi_secret_theft_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Fake Payment SDKs Show Why Dependency Risk Is Credential Risk"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/fake-payment-sdk-npm-pypi-secret-theft-defense/"
        date = "2026-07-08"
        net_indicators = 5
        file_hashes = 56
    strings:
        $n0 = "api.paysafe.com" ascii wide nocase
        $n1 = "api.test.paysafe.com" ascii wide nocase
        $n2 = "caliber-spinner-finishing.ngrok-free.dev" ascii wide nocase
        $n3 = "ngrok-free.dev" ascii wide nocase
        $n4 = "https://caliber-spinner-finishing.ngrok-free.dev:443/" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "1314fc888ca5b3ea91a04e1f5b63039ffc7fc3832b8d809a28ad549c6f9d4f23" or
        hash.sha256(0, filesize) == "1bae9f2fb9866422f07345501fa2cb4c3a99f2652c8c9decdc27ffbf9714e7bc" or
        hash.sha256(0, filesize) == "1bfa32548676d32b7639d3171e2f9feefba5026dc336968c91f4ae2b152c5410" or
        hash.sha256(0, filesize) == "1d567795a366b9edcfef7f1fa2d398b7cb41890dd3b2f3f1f9803de0cdba0c89" or
        hash.sha256(0, filesize) == "1df8c579ffcbf5527b1856bd1774601a5188b380e442c5a0fbd400bd86a4501b" or
        hash.sha256(0, filesize) == "2303a74a5fac917279f1078e03a4bfd6afbb89462f97d7344ed10e6e9e9e92b7" or
        hash.sha256(0, filesize) == "2b7696575278e6e223cc44553c687e45afd04df7eb32efbf49b39da64b795982" or
        hash.sha256(0, filesize) == "2bc8af4bd2f539630f7800f3491b64c7e2bffe12e955d0d4f03a4f6a4b0018bd" or
        hash.sha256(0, filesize) == "2cbfc4e4b1de5e68ab81fba7e1b0c711b4d26197b48ea4db6819c9cea223b0ed" or
        hash.sha256(0, filesize) == "2edb3f162f9676196e818d9b795d599ba119a961ffe98c4866351735980d213d" or
        hash.sha256(0, filesize) == "313853a82bce61052c00e6a6af85b5069e007a76122c727f31661bc636b12f14" or
        hash.sha256(0, filesize) == "390bca9d70efa42cb792f7f677189821a24527cd4298ab2acb954df0abb5c1c3" or
        hash.sha256(0, filesize) == "39371ac7061168dd3d890061267b3875bc4b30dca5e28d40dbc27a4396439ff1" or
        hash.sha256(0, filesize) == "3a0dd3479eaf85b65e5abd63d6451f98506faddee47cf4bebd9f91296abb29f0" or
        hash.sha256(0, filesize) == "447484c76a06918d7f6f6c6f95ee2bced6dd2e9b282c6f5b92b2b7c0976381d5" or
        hash.sha256(0, filesize) == "4a4b5c1bc1e948c853cb0978c07c7b8d1540c7b1ded95f8d5ad25c126cb6c7b0" or
        hash.sha256(0, filesize) == "50cb7550224d8d227a0625e7f53be86924d8e057e403b6b91b83ea20df834048" or
        hash.sha256(0, filesize) == "5242c5086d75a492d14e474de7c8f34b18ec0a8a9ce6d77eec8675a9572d9d23" or
        hash.sha256(0, filesize) == "52a57c502e40b3f9897d0ca32bba6f844b4113f5c017627ea9eba660eb47f405" or
        hash.sha256(0, filesize) == "5c4faef80c83c7ec0925a4aacb4bddabe82b91066ac41305907ba277cd7b3b85" or
        hash.sha256(0, filesize) == "5cd62e708ae4393c99579ec1433571998299bf7e2fde9bafeb9a79f8bdf065e9" or
        hash.sha256(0, filesize) == "615805652b2f006e69512b90d0d63883d7ae1ede69d86384fd77bd46235b2369" or
        hash.sha256(0, filesize) == "616b41657e9afaa9354fc1a106393373dcbf8aac8455b7d2cbbb44463434528e" or
        hash.sha256(0, filesize) == "61b61dd25cd8dcc43cd78418f3e3eb3fd9002d9e49961eefb12c1022ce4c3b63" or
        hash.sha256(0, filesize) == "67e4d6a4f53098e48bfa6ecceeaa754592bc249b83404bcfb8542977ae36dac4" or
        hash.sha256(0, filesize) == "67eb3bd505ebfffbd73fc3ef0b2976c375df732f0bd0496ed6653c3e2be5a0e5" or
        hash.sha256(0, filesize) == "6dc672e3bab8bcf80c66b2f95150067fb47429d4cf65eb95215e5f3abc7cade5" or
        hash.sha256(0, filesize) == "6e251c3d2bde8fff0487c1eecd359c4a544a09fd708755020e4b1c53ad6b8dd1" or
        hash.sha256(0, filesize) == "727fe9c1dfa39d6590012e0593c9837c628fc2cd22aa0f4e486b7ed1aec02697" or
        hash.sha256(0, filesize) == "8a58e3ed713c1c70f421ab56a18cfb6a120c960d227e495b511c2552f25f188b" or
        hash.sha256(0, filesize) == "8a70a5c1075f2dea4db94633ddc64b0d03d0385fdeda7c226acc944331febf43" or
        hash.sha256(0, filesize) == "9727c804c4354e481d2ff9d4934bd1b2518293a9ca34a14f5c7ae9d0cd30ce94" or
        hash.sha256(0, filesize) == "9e9655f54bfac8a937d78ac506722bae1468ead4cc9ee95b35e0f8ef17ee13d9" or
        hash.sha256(0, filesize) == "9fd06d823d54183cc91625fdc6decffe8db2863f6499a955656ebdcc089792cf" or
        hash.sha256(0, filesize) == "a0313822513f9b89479f666888a4784a3fc99b4cc4566213dcda66b03b47120c" or
        hash.sha256(0, filesize) == "a677c02e545941e43f8b21a5761b035e911b53e2c065fea219e0f3462f282fd8" or
        hash.sha256(0, filesize) == "af66bc2b516d1ef71af9b6ee9f8f5af0a99fed562b34809cd55071b94c2d1304" or
        hash.sha256(0, filesize) == "b04daeacd1d1c9020cce2a97fa7af83dbedf4e6d17dd12c0f337f32240399785" or
        hash.sha256(0, filesize) == "b157a66826d27512c3618817fee924e53d14cabb2c4c7f454affde37350f55f0" or
        hash.sha256(0, filesize) == "b29973eda4d0c090608c15a976688cad0b2114fdc0dcb89ad37515287ba13aad" or
        hash.sha256(0, filesize) == "b2ea8d69f6792a87327ffde2ee4551bb6b99617f53e1ba71bf9a70f45dbc57ea" or
        hash.sha256(0, filesize) == "c2a361a7d8feb95be97c957fc7652d348f4fa9a987bde5f09883f46b65c460f1" or
        hash.sha256(0, filesize) == "c2a69a33b086364ca51b030b6b15e99be46ce8255ddf62839a4fc7f2b34023de" or
        hash.sha256(0, filesize) == "c2e4483abea830ba8b8230540ace51788d0712bed9006697ddddb9cbf133c151" or
        hash.sha256(0, filesize) == "c51c0b6c7817443b021aff44d4416c09fd039849db81860b9b5144e789fa3987" or
        hash.sha256(0, filesize) == "c6af37a6739f0d919ab7049caf3a85831cab44bdbea27e0d9de7adec80334e2b" or
        hash.sha256(0, filesize) == "c8b4d17c1f0aa7c50f2fa23d7c328482a4ad2c4da4d600f358ebdf200cbefd83" or
        hash.sha256(0, filesize) == "cd7255730b6a7a3895d622d37d0e8f984d2d280689acef56ff195d663e7723ad" or
        hash.sha256(0, filesize) == "ce09810adca70ebec87bc455380ef629ceaa2a0d926149d9115604060167682c" or
        hash.sha256(0, filesize) == "d1889d81cfa99d52017732da9dc52127d03893037874c8671943cede4b8d1bb2" or
        hash.sha256(0, filesize) == "d4ed2d87942fbefa5d7b7f19fb6f2e9bc293c96bf577bb97ed3ca56185abcf25" or
        hash.sha256(0, filesize) == "dabb47d75f2efa6a5540661484efa989ccb338f24938b23152f14f3e424b0cb5" or
        hash.sha256(0, filesize) == "e076e13a7e112d364f03bd1ead7abaa83249d544491621254860ab0a73adc9b9" or
        hash.sha256(0, filesize) == "eae055c5736366811d2a4b1f78ff206486e7f7445040122efbe023ecd2d20bcc" or
        hash.sha256(0, filesize) == "f43cb68850a2506805d60ff466f54eba331e1cc2a513b329f5121e0c39104418" or
        hash.sha256(0, filesize) == "f7d9865ea3874d2b135eeee0aa0d12fc108d89e1dd706e4e40eb7605b76d35ca"
}

rule BulwarkBlack_vidar_xmrig_malvertising_file_size_code_signing_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Vidar Stealer Campaign Shows Why File Size and Fake Signatures Still Beat Weak Controls"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/vidar-xmrig-malvertising-file-size-code-signing-defense/"
        date = "2026-07-08"
        net_indicators = 10
        file_hashes = 105
    strings:
        $n0 = "116.203.243.208" ascii wide
        $n1 = "136.243.203.109" ascii wide
        $n2 = "136.243.203.111" ascii wide
        $n3 = "138.199.246.13" ascii wide
        $n4 = "BleacherReport.com" ascii wide nocase
        $n5 = "ip-api.com" ascii wide nocase
        $n6 = "justwatch.com" ascii wide nocase
        $n7 = "pool.supportxmr.com" ascii wide nocase
        $n8 = "ip-api.com/json" ascii wide nocase
        $n9 = "supportxmr.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "1aae8bf580c846f39c71c05898e57e88" or
        hash.md5(0, filesize) == "c10333c92889b65c3590ef2b3819b420" or
        hash.md5(0, filesize) == "d42595b695fc008ef2c56aabd8efd68e" or
        hash.md5(0, filesize) == "d8b31f8c03e0c76ff245ed05a15ffe6c" or
        hash.sha1(0, filesize) == "ab92f731ab20774dfdb95664ee41a2fbafe2a284" or
        hash.sha256(0, filesize) == "03e6f4f49cec3af38bbec9ed64c195c7a85a630ec989efb3669f04a2993c1dd7" or
        hash.sha256(0, filesize) == "097a87cfa4a5186aba3bba096866692951bde59c6f0c2e8c1c4a599246d14da8" or
        hash.sha256(0, filesize) == "0a6a67a2fc4d79ec1cd8afc5b8b7a5e69a406e53d57a7334e097c5d0644de5f6" or
        hash.sha256(0, filesize) == "15489bcd6e4602b41c9a787ec8d7ab027d5e45d400938048bb1c702ad5937980" or
        hash.sha256(0, filesize) == "169a330353e53a409e0109c914404354741ff1e1c64e501738dc05e58ea92abc" or
        hash.sha256(0, filesize) == "201594c9d173bba6cb509407ecba378c19b93da0a81a2182a913c480e6dbb54e" or
        hash.sha256(0, filesize) == "20bf39e1e67152039e70a01ad9e7b23c08d23d2a724ef9c44903f3d4353a2275" or
        hash.sha256(0, filesize) == "2a02ec4af5ed591afdf1236a443e3b68642ee133f38a2857d1eada51246ab498" or
        hash.sha256(0, filesize) == "2b7297a5f502a2e9a59066f0a370bc5a8b28addd0e27975db3d770f801c15397" or
        hash.sha256(0, filesize) == "2c0b344af415b787b396c8e23bbeb112bd471a1ca1d12cf357c48e2ee1ae068c" or
        hash.sha256(0, filesize) == "2c6e8f86c05781af12b323311e83e011f1a603928e2086c48e2ca59e33d90dbe" or
        hash.sha256(0, filesize) == "2e11a16f94484e0f43eb4572f800f26f0b4a1314cbdae3c44c1ae35f376906d8" or
        hash.sha256(0, filesize) == "2f1400a91c853d61622f4d21ed97d96ea1093c0fa1586669bea6f6baa331251f" or
        hash.sha256(0, filesize) == "314ce675c040c63b825f213965f5c76a3bd09bf70e138708367e2a84e9e84b30" or
        hash.sha256(0, filesize) == "32172e4d8d2ab9fb29b36c9b279117be6ff611b5b91ff7b1c42501a5ec969f2b" or
        hash.sha256(0, filesize) == "330efeebba3782994612fdfe20ff96c930af33a83b88a342b6622461511921b2" or
        hash.sha256(0, filesize) == "35b51bbe42edd15918b015eaa1b4f0e6b5c94f186d71d887e39f1da69a4dec3f" or
        hash.sha256(0, filesize) == "35dde1b2482b12582820a861e7c46f10721af6b75052fc872c05d2230a4e8ca1" or
        hash.sha256(0, filesize) == "3c3f12531045b7eedfe25e0f291d4792b0d8c8366f8de043e2fa8ecf34ccb913" or
        hash.sha256(0, filesize) == "3db33b0423bb9278db267a7adb036ecbd6aeebd7909d06d824919708b1e12e1b" or
        hash.sha256(0, filesize) == "3e906ae47e9836a591f44d4b743e961d634a404fa8fd8bfae64f1d54c853be2b" or
        hash.sha256(0, filesize) == "43920ef7d2742d140a1ab2a1ef172c716903474c73561377dc4f1534d2c5f581" or
        hash.sha256(0, filesize) == "47d6d1a38534ba897a5a1e293e3d5df303bbd8e0526e756ad08887ffc1417bef" or
        hash.sha256(0, filesize) == "488d941b7b4428b0f4a0e5495e3857b9b96215fb3e7f164b06640d59096425e6" or
        hash.sha256(0, filesize) == "4bf770a59d367b532dec32668f86003b17d93918dba5ef5fd2b19c5394252436" or
        hash.sha256(0, filesize) == "4f456142caf590d98fb11ca247800bb417766714527e5a4707ac2f5d01542626" or
        hash.sha256(0, filesize) == "53d263b292be387843fadb7131c2d538b4262c81f5b95cfacafacf2d5446c06e" or
        hash.sha256(0, filesize) == "5494909e0f5221db75e933b28981b2d0e118f227b7d8a5980d88b500b76dfc2e" or
        hash.sha256(0, filesize) == "54dc05ab56244444f86d69b8274a6075906f7ba2307b08e08d3884abde255495" or
        hash.sha256(0, filesize) == "559f46ceb801a3540eace594476718e1486b5b4423cfb4ff64530ff8fb4a3815" or
        hash.sha256(0, filesize) == "5838ae6c748dcbdfa13c6529c654cb821897d29835d3e7e05ca23fb2f3794f02" or
        hash.sha256(0, filesize) == "59b9153c4c9e155c976db1a2fd4d1b28fa10bb9c4dcafdc4758b352c037e3d86" or
        hash.sha256(0, filesize) == "5b6a466b65d479b77a03b15a95ac097b45e23ff7ae5ef6282985b2a503deb691" or
        hash.sha256(0, filesize) == "5d7324d8b5a25f862ef8223c6766d0e80af3ad168e17312b265e13a3a68e0ded" or
        hash.sha256(0, filesize) == "613e5314a7ded3155cdec49fd34e852e181f4651d78bd8bf3adad2f4dbf22b0d" or
        hash.sha256(0, filesize) == "62877a5096828c4bc2fca7cbee7d38b11a0c90fd0d3fc8c37981581e9988c919" or
        hash.sha256(0, filesize) == "634e89d8592d7c9e2bc1c098217a813947b44a4f80bc569e9a15c1e8b0864b91" or
        hash.sha256(0, filesize) == "67569adec99fd38b114ae07e2e549e6c16f75368f3c5373022c84934ed1c8e84" or
        hash.sha256(0, filesize) == "68ced9d7c1b1ff8ffb5f56c7d3f849d4fd16a1b95324426811424b40043d6d25" or
        hash.sha256(0, filesize) == "69946018ddda1058ce5c2a556c78a747838865c47074dcb165effb0840cb1cf5" or
        hash.sha256(0, filesize) == "6b7ff061eebeb9ead8812c410247768a7ba90786aeeb1bafa6412cc5b08237b5" or
        hash.sha256(0, filesize) == "6d49233b1fca22f3823e856e4c16749e9c45f384ea57055fead16df35b217226" or
        hash.sha256(0, filesize) == "71c79e8bf71ed257435ea9b8b91e118ba03ec681860651190f7d7457804313ee" or
        hash.sha256(0, filesize) == "739cdedb20de39aeb1f15dc8c2dbbf15fa993250fd879bf87443ff9aeaf4997b" or
        hash.sha256(0, filesize) == "74df77b6a83d89fa137fd285a2efde36b1d62c00b3be81cc93df7d1e6e94837b" or
        hash.sha256(0, filesize) == "7720e83c02a027d70ae201c393c1956aa2fa8199879a3a4c4fd1d20b03022cfd" or
        hash.sha256(0, filesize) == "77469615c5f548063922b469a8c0a4116511395d013e5a798e123e9c119acc4b" or
        hash.sha256(0, filesize) == "7828e17e674507ab13dfd84b31b361fa19b9cb27ee130620ba9211feef746d31" or
        hash.sha256(0, filesize) == "7e49da0ae2f81e14841f356b4d69f0480c2d9ce3fab5a3fa91b0036d9a36fa0f" or
        hash.sha256(0, filesize) == "7ed4a256e1d281cb4f194d13ff554fd4fb280dafde0a67a18115ea038ea6c87d" or
        hash.sha256(0, filesize) == "8b40cc7d173efd27fb60f3d260acef28f58d67d1f39597e1d611db311a305f62" or
        hash.sha256(0, filesize) == "8dbcde2a28a0b3de201214d7e3bd43acc97561924daa247c05c4b0536d42be85" or
        hash.sha256(0, filesize) == "901a43b42f997710147295a0625e20c935207f8c531daf5311449ec119a37dcc" or
        hash.sha256(0, filesize) == "914c18a04a2727bba9cecab78a1d516ec3c7a3f667e0e5a6081aa0e9206a69fe" or
        hash.sha256(0, filesize) == "94db6fa14b4e487dffba709b87e8a7e25483300ed409de243b19fff7cf2f0978" or
        hash.sha256(0, filesize) == "95cd48130247525d8a7e966bd3fa07e9d6c39ebbe3058ecccb336f66bb8e3d1e" or
        hash.sha256(0, filesize) == "9656d3301f63ef6114289739a1c44082206298f787238fc6c190ad87eab24751" or
        hash.sha256(0, filesize) == "96bb418128deeb2b9d2e4b66b98cae07b238b326b6456cc9b86802e67c504a03" or
        hash.sha256(0, filesize) == "98cce1e69873de25e5139aa848f469bef2af345a8a49d15000b5b5e72b582896" or
        hash.sha256(0, filesize) == "9b3df1b6c1b98c201de09a7719066f7bcae6b66a3173b703a617f53fddf67d51" or
        hash.sha256(0, filesize) == "a1039de7ec690d64db9d7d91f3d777d308e49e958de4154aa0b62ded7820f1fe" or
        hash.sha256(0, filesize) == "a17a972a05afe387ed32aa2986d5be8bca2f22619d0aedfa834c6963abfab3bf" or
        hash.sha256(0, filesize) == "a4f979b4a5d7bc8bc455dd4c09b44e51a389576fccce35a2c8da3ce680237565" or
        hash.sha256(0, filesize) == "a64843ebfbc39e96ec7613003b1b5c3a9b878874ea15a05e1d34ce91781ebfb6" or
        hash.sha256(0, filesize) == "a785fc61fc4ff7cff0ddb540bf7ff12111ed0d6031f78f48387a6c16cb3c5451" or
        hash.sha256(0, filesize) == "aa0083f662f055e8d911c5de3a8f3a31b3c84cacc7dccc30c98f2be14dba4102" or
        hash.sha256(0, filesize) == "aaa2bc1128d8b8b2da76262bf87ede19bac053cca6576efba6aaa71c9438c304" or
        hash.sha256(0, filesize) == "b58814fb3ce5a085014ee6e8d89f7cc1380b234b97170fd5f3398031281c6a77" or
        hash.sha256(0, filesize) == "b6912c23cccc4b0964d55608916297f6978f0b38c80a4beac472004a786fcef7" or
        hash.sha256(0, filesize) == "b830f043076a12748b6a2dc0810ece85439ee77434d991ae7d84201b09ead756" or
        hash.sha256(0, filesize) == "b8b5f6991a3a61083461d5269245bebf28b90934c328848ba8c1e084a5a6216c" or
        hash.sha256(0, filesize) == "b927d265fa29e471c1ae0d31516e480c09c0fb17f480ad08ea8d5b73e84b7a1b" or
        hash.sha256(0, filesize) == "b9b6893fa6b04ee8daa29e515c08239ac5204af1a1fa2bc10006eede1b41329b" or
        hash.sha256(0, filesize) == "bb30cc2b302d9a6963109b201b78d4163bb6c2d7bc8bf5a66e9a744b62fc2717" or
        hash.sha256(0, filesize) == "bd3230e4ceaf32ad2248ab069b164bd2144401967ac69de0a4cd1734fe429d9c" or
        hash.sha256(0, filesize) == "c25799facb3e788830bcf614f33411d3bcfc0edd4a2200e160b5eb4ce700039f" or
        hash.sha256(0, filesize) == "c328b78c21060e2203ac517833fce41572b91878e187f85fa434cd6914659834" or
        hash.sha256(0, filesize) == "c39fedb662259bd76b11616966c41ff1fbda58d9b129b9c1bd818700eea92b29" or
        hash.sha256(0, filesize) == "c7a4a547eb7f6b0b4b75bb6dd8955244bb2618ba234ae740cdedd7c2d30e3465" or
        hash.sha256(0, filesize) == "c7c37a973b14edd5b6b2da4a1497c593e43640735ff54aecc9a3288fa5e548e3" or
        hash.sha256(0, filesize) == "ca8a00c9d36c64e5dcf562c7ae2b8df4bd6455fe0b41b32ee3a2a528ddc2d155" or
        hash.sha256(0, filesize) == "ce379de03e35e0ea2c88744c29b9e2678165214065f9b957177002c6bbe69084" or
        hash.sha256(0, filesize) == "d18369be4487d7cd0e4bd3dd0da720672e56e13ca43627305e26767e26925551" or
        hash.sha256(0, filesize) == "d2148a458da46e81702136aa915312d360805f083d1f37ff5531db9fbdb8ad6d" or
        hash.sha256(0, filesize) == "d384c403c084967d8c967501ee6332b050af04ef424f13a3f5a88d155389d98c" or
        hash.sha256(0, filesize) == "d6446f2803444bd2200d48a01a9ad7d487e67e8e831c9cd13f89cbfec17fd4e2" or
        hash.sha256(0, filesize) == "d7745513034af14617436ad6b3fc125fd0343218411d0c79bda56b0dadc86b2b" or
        hash.sha256(0, filesize) == "d78082dc33c6dca98316e865efa9829c6eb5a97c2ca3cd4ea6c2123a5f6ae45b" or
        hash.sha256(0, filesize) == "d7b56818c829960b692de9ad5a14e52669d953e9f074f7218c3fe34ede4a11a0" or
        hash.sha256(0, filesize) == "d7c9c9469c513c05aa431fae34f414f91fcf3f794d3e76b6e4d0b92c4cd3ff2e" or
        hash.sha256(0, filesize) == "d8ac0c08e4c698017558e532974cf749135d3d49757f05001e6127dc6e07cf17" or
        hash.sha256(0, filesize) == "d8c1f96107a3349e62b3ab9afc60f62af9c89b6961b637a26b71e1230f2b3b8a" or
        hash.sha256(0, filesize) == "db2a872f712fbdb1e347d06e29a9ed8278d86710ffc14ff04422be76e47124f4" or
        hash.sha256(0, filesize) == "dccf9f008b42a04f7e69d3bbf7b5ce81e71308545d6176cc4763920a424e5ac1" or
        hash.sha256(0, filesize) == "e5341edb7c039c456d46c39f194be86ce4b41725d7ad12d297d18aa99cddd675" or
        hash.sha256(0, filesize) == "e88c41a6f769cd760e323b4f7c01835433cd4059cd59630cb1a9eb1181b350ed" or
        hash.sha256(0, filesize) == "e9e5e748ec5c0b811c8e60b0e55059edb4d2df86ff3ca45969e57d5fecb11a38" or
        hash.sha256(0, filesize) == "f0dcb7e407de85d8de8e2221df8dddecac8aec88af8975c9f07e14100f6edb88" or
        hash.sha256(0, filesize) == "f13f9cef5cc020bf673c7f4e19c93c312a043867f46796a8f01927a9a14c2533" or
        hash.sha256(0, filesize) == "f760bc16a585325ba9d74917f9e0994d3a4164c1141158c799b619d2c823e818"
}

rule BulwarkBlack_uat_7810_orb_relay_network_edge_device_defense
{
    meta:
        description = "Indicators from Bulwark Black report: UAT-7810 Shows Edge Devices Are Becoming China-Nexus Relay Infrastructure"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/uat-7810-orb-relay-network-edge-device-defense/"
        date = "2026-07-07"
        net_indicators = 13
        file_hashes = 77
    strings:
        $n0 = "194.233.92.26" ascii wide
        $n1 = "217.15.160.247" ascii wide
        $n2 = "217.15.164.147" ascii wide
        $n3 = "95.182.100.231" ascii wide
        $n4 = "http://194.233.92.26:2222/" ascii wide nocase
        $n5 = "http://194.233.92.26:8088/" ascii wide nocase
        $n6 = "http://217.15.160.247:2222/" ascii wide nocase
        $n7 = "http://217.15.160.247:8088/" ascii wide nocase
        $n8 = "http://217.15.160.247:99/" ascii wide nocase
        $n9 = "http://217.15.164.147:2222/" ascii wide nocase
        $n10 = "http://217.15.164.147:8088/" ascii wide nocase
        $n11 = "http://217.15.164.147:99/" ascii wide nocase
        $n12 = "http://95.182.100.231:2222/" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "0352f3e338261d98895df4c7b7a76b296485b2290c72bce56603351d167d0601" or
        hash.sha256(0, filesize) == "03926e3da998f32ad898b640bd15cf145768f9e849e6f18d81350234254c424e" or
        hash.sha256(0, filesize) == "08701ed7975bf4f5688c2724d27ab497764200ad6f4dc53d3cc03b170378ced0" or
        hash.sha256(0, filesize) == "0a8555a71868749be8c905ed53296ce335af50a9262772b5e154ad3f9c35c2e4" or
        hash.sha256(0, filesize) == "0a8cae96e25e85c612b0736fe886f9b124ad70ec425bc2ec1a8a4135b25436ba" or
        hash.sha256(0, filesize) == "0af4c52a1d13e4132a1843ce7727abcf0ddd4d1ca6a4b17cdf599ec3f355c241" or
        hash.sha256(0, filesize) == "13acadb3541e75af50e02d5be56c2238b93d8f154ce5514be1558e6ee59a1432" or
        hash.sha256(0, filesize) == "1660536f448b8b9f086ce9ea3ce4e9deefc59a76711ea53ee6d8f08fc8c1bb99" or
        hash.sha256(0, filesize) == "16971f9706d70ac4925651c7c8719b9d77aff63e4c0a618129efc32c2c46b989" or
        hash.sha256(0, filesize) == "1b5649b479fd625de5c8120873644b5eb669cc89cd504582c18e0ae350fd8823" or
        hash.sha256(0, filesize) == "20fcba222f74dd68aaeb1f0ad30cdf702a828ee164a182b30d05d600c35b72d9" or
        hash.sha256(0, filesize) == "29686c933cec1e274467e2dae264625ae6f754824bb7f550bc9c3131f625562c" or
        hash.sha256(0, filesize) == "29c7fccc6ef8cbfe4da9a169c7c74bacaea1fb515a1fddef91ab1b1522f76e4c" or
        hash.sha256(0, filesize) == "2e0e43776e2e1a37d882a1b2ebb7d337ee88950177e43831dae645a367824feb" or
        hash.sha256(0, filesize) == "2ebc1b6cf543e2cb3f22d9a5b54b6676bb71dde98df7532f8791297734e44fdd" or
        hash.sha256(0, filesize) == "3169a6dbcce684e2c5a2f166996b58ffa673df6e58b8edf2bdf3e66271c8c69e" or
        hash.sha256(0, filesize) == "323c3a91be60ebc3e06e942bad04899a15911cea23269e43d07829164b2ce5d4" or
        hash.sha256(0, filesize) == "324d95024fc8da5c92b5a1f4825aed5a2a91c9ca8fb6aa52abb332a4c9cf4257" or
        hash.sha256(0, filesize) == "33c10b77e1da9f0679023d55fb3057879d15609db9c1d46ee5c3ff1240a3d052" or
        hash.sha256(0, filesize) == "3878dd5c8eba1e5b53ab2e07e7b5482e95a3fd3e98268bcd7861318bc9902376" or
        hash.sha256(0, filesize) == "3b89d183eb014e29d9d0d4e45fc2b784a7fcfcf31dd48fd3bde30f8d956383d1" or
        hash.sha256(0, filesize) == "3d296af7f29c0425655bd1cc0be48fe4aba52ee6760a89e805ca2589f4ef4d77" or
        hash.sha256(0, filesize) == "3fcaa3038e365b6ab0b121e2cd319c56b74e37381943a0da0e8dce407087cdb8" or
        hash.sha256(0, filesize) == "4130f49fa81a699a667cafdbd6d1f6e781edd686c947eb8ae27134f6dc2c43d7" or
        hash.sha256(0, filesize) == "425bf771c8c9f740b1ae9803dcb4fd45af4d6a6f171fcc72fc7d511095ca82ce" or
        hash.sha256(0, filesize) == "52b871429833e1dee348263844efb531f6a3fcd321f88dc8a876caaee912cedd" or
        hash.sha256(0, filesize) == "534a4a5bff2609a2d6e088cb87465c08c2d69c6aaa7d2ffcbcd491274b8505f1" or
        hash.sha256(0, filesize) == "53ac2b231c23d41234e55b1f7ed89f86234f785adbbe820959655d7b019d7df9" or
        hash.sha256(0, filesize) == "57bdab2ba4b05ec0338c06632599393d5b14227f31a43fe950ea8fdd47428715" or
        hash.sha256(0, filesize) == "5c3f190571645c4641dcff2c07a4c3ab9acad06aa9607350a385729d8d6139f1" or
        hash.sha256(0, filesize) == "5db2ce9acd50f96d566e8d139f6490abf2bbf7a9293b876eeb4598fd2c37c515" or
        hash.sha256(0, filesize) == "5dbfa033676b5caacfae902734ce462cd871181eefbe299250ca8ac7e139719e" or
        hash.sha256(0, filesize) == "5e225ea2648a8cba0fd94ec7fd8ce5315f5d0cc2922bafc9db3c8c41280e917c" or
        hash.sha256(0, filesize) == "5eab4c61baa67ae2838a36c2e6ff0476a8f2117b96a7027b830c8cb46ce78efc" or
        hash.sha256(0, filesize) == "5faea1650cac0f3ffd2dc1fb220182095a46e34158967d37c2a942e85e2ca97b" or
        hash.sha256(0, filesize) == "604b53f87d6c070bf387e80c70a6df8d272fa3fc143148d41f13e59d52ab1f13" or
        hash.sha256(0, filesize) == "62d4ec87ed21f0d15cb769b0b2a5577cab41fc2cdb1e7e796c5bdff09264dd9a" or
        hash.sha256(0, filesize) == "6366d59b573d50fd23ff650923c4a8c1c918518a02d0a56f12c23533c45f439d" or
        hash.sha256(0, filesize) == "65feba2c971c214e71303ad2e0fbf62b45ebcaa784cbf3d0dab62786cb4c0469" or
        hash.sha256(0, filesize) == "68445a37a9943a267a8b2100fba2678353d6ec88844505ccbba659e586c7a105" or
        hash.sha256(0, filesize) == "6917c0f9eafefe42e33e791b75a7e503ff8b081bc10a98449e4076787dfc6c16" or
        hash.sha256(0, filesize) == "6cda1e81667f869940401f05a55c8dea94dbdf3ceffb93b5f320a6462cfea44d" or
        hash.sha256(0, filesize) == "6dbd507ca7cecea861f9cf704b3c5c37f5bd5392886a8c2562088892b7703fa5" or
        hash.sha256(0, filesize) == "745538dea8ed9aec4466e67a9d0aecf9e7026ff16a792d1d6f306e8b67d3f34c" or
        hash.sha256(0, filesize) == "755fcee1337a252203002ecfdf673a08cfadeda8d738bef2d518a08e0626aa4f" or
        hash.sha256(0, filesize) == "76d9e2a2ff313f5b91cc67aab1127122baee1c3efbae1087e58a25bc5f1eb065" or
        hash.sha256(0, filesize) == "8459ff264a2c81c68a34c4ee6bc109d141ad28b96037d34ff112322a4c853739" or
        hash.sha256(0, filesize) == "880425fee707e9f42e0b8d60119ed639b1ad506ea29877d126bdebce379cd229" or
        hash.sha256(0, filesize) == "89f0a67bc595ab8bce02c2f95f9292ad06e1868207e809c76bd16f0cab800c06" or
        hash.sha256(0, filesize) == "8c104da0e66ef6384663309aaf8fb49f549f2785d835eec620b265f8aa11d9f0" or
        hash.sha256(0, filesize) == "912adea5339c73cb4a777a3e9f98bf3cb08da6622c9dd3b4cc9b083cb03d10a2" or
        hash.sha256(0, filesize) == "9a927c37a31b80975c5c5467f112b61478c9493c046281046443525358a5acb0" or
        hash.sha256(0, filesize) == "9b9e0e5a1eb469b8d20dc23351e08ff5d5731e1cedce0ddee9bbd00a76217f13" or
        hash.sha256(0, filesize) == "9d52cb4febf3342c34dcc8198dcaf453458be3699ab47dc08616aa7f18daa7fa" or
        hash.sha256(0, filesize) == "ac8eae94d27122f4751bc96d9ea52d30000b7ca37569a2291b2710824ca3396f" or
        hash.sha256(0, filesize) == "b5969636eec376ad6c3ece2202b1722219955638e09b6f96d4cfc0598d3b1890" or
        hash.sha256(0, filesize) == "b8d247fd1fb85d24a17afeec3815906dfbcdc5359647910b4a153900ec999a0f" or
        hash.sha256(0, filesize) == "b9fe48bda9a6c8787981a24f8bbc723a6f6aa80cab5fa53481937382f3c6ce85" or
        hash.sha256(0, filesize) == "bafba443170e54ef7fd431ce7f1b5e202719f3fd022e4ef70788904f574d2cdf" or
        hash.sha256(0, filesize) == "bf70c6f3a8e913f526ec57eeec50e1306f7b34b037915b7a1cf2968cc46acc58" or
        hash.sha256(0, filesize) == "c2ab9adaba93ff094b8f3fc37d906014d870582039d276b7bd03e6fd583d8a15" or
        hash.sha256(0, filesize) == "c494c878e28284539419612616d964ab9224cbe27e57f42293d91d02d684e3db" or
        hash.sha256(0, filesize) == "c7c9bfa9ffcd8fb6a2afe656f510c406ddc58ebff48ce1d0fd3fad951b46a36e" or
        hash.sha256(0, filesize) == "c92541f273eeb576d39235d0a5c6f18f2574b132a1022598edfa38065783ab98" or
        hash.sha256(0, filesize) == "d1f963b88672f3676a7da1580262ba0d4f367cc57a94b551754c20f77a670c43" or
        hash.sha256(0, filesize) == "d4861088161fc72b9922abf933b4ea664a807105ec1eab4a173253aa60bfe6d7" or
        hash.sha256(0, filesize) == "d5cf7315186a78ab6a7475c338bdf101bc6461930aaa7a012a02cf93f347c207" or
        hash.sha256(0, filesize) == "d81201d0fc19977e51104438a5b9cba861f4da20cea3ae9183edf16ab11d98f8" or
        hash.sha256(0, filesize) == "d871d76171504597bbda387689e12e7a5e354c360ff135f4df231cec68c761af" or
        hash.sha256(0, filesize) == "d973ad5a80c3d7468a9c392db4166857ed32b5d61cd6755766ba8922156dada3" or
        hash.sha256(0, filesize) == "dc4f25b2247cfdd6fc96848db30a178baa4419a4c854e86e315b465836102d14" or
        hash.sha256(0, filesize) == "dd0fc1a88180fde8367bec7086f99294f36b8332f12994293139ed532d2ebbac" or
        hash.sha256(0, filesize) == "e5d2de8ae98579bfb940290f60e59a502b3065345aaf765456387989c0488b20" or
        hash.sha256(0, filesize) == "e799d72929d7ccc7f6b6109742b8cc482838303207efc989543b6e1ca6d16e9c" or
        hash.sha256(0, filesize) == "f235d2e044c2f7814e6bbcd835b9fd9f10f227dacfb9396185ec2013e7df4db4" or
        hash.sha256(0, filesize) == "f3fbf4481f30fd840f35568746f54be49eb92b2c9ac95597a7760abb171cb54b" or
        hash.sha256(0, filesize) == "f5a57dfae488d9dfe260b32460a1d947fb5af58ceaf2fb0139bc08b4bb79a966"
}

rule BulwarkBlack_ousaban_banking_trojan_iberian_phishing_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Ousaban Shows Banking Trojans Are Learning to Hide From Sandboxes"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/ousaban-banking-trojan-iberian-phishing-defense/"
        date = "2026-07-02"
        net_indicators = 11
        file_hashes = 20
    strings:
        $n0 = "162.33.179.46" ascii wide
        $n1 = "213.159.64.191" ascii wide
        $n2 = "78.40.209.32" ascii wide
        $n3 = "91.92.240.140" ascii wide
        $n4 = "controlfacturas.site" ascii wide nocase
        $n5 = "duckdns.org" ascii wide nocase
        $n6 = "facture-arsys.duckdns.org" ascii wide nocase
        $n7 = "facture-in.pages.dev" ascii wide nocase
        $n8 = "faturanova.duckdns.org" ascii wide nocase
        $n9 = "faturanova.xyz" ascii wide nocase
        $n10 = "pages.dev" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "18fd38988d58dd930f5992d448cc09a9400c1eafba76b820b9a83239ac48cf4e" or
        hash.sha256(0, filesize) == "19ac18a50abb48dc0ea9524850acfaec49359e6b3bcc67c6193c2d56da812c71" or
        hash.sha256(0, filesize) == "1e77992666acbbfa0d01fcefa9cc8fbdac291e0681b35745be27c6dfb159a375" or
        hash.sha256(0, filesize) == "21b24f7ee1f6bdbbb670f0394d66009ee0daa8ced57048298da715e88f7a7cdd" or
        hash.sha256(0, filesize) == "48723a33bab89f174750576f9a62da35b3b9e5ac31a5a8f1ce9859a1b35bf8b8" or
        hash.sha256(0, filesize) == "4c9fdc2823da505ef339d43c6ad38499b7e3447736733e42b5ab6b1afcfd42aa" or
        hash.sha256(0, filesize) == "4ca2c863d740bb7022776dccabd8ae34bb9998768928042d76ebcf08984eefcb" or
        hash.sha256(0, filesize) == "540ee1936e61d2344b5ebc93485589a351ec2f113a9b4940ae16f3baa4807392" or
        hash.sha256(0, filesize) == "5837e47198a20877e1b04b270c36d9194206ee38d4f32fe3151b3c3b396c4f0d" or
        hash.sha256(0, filesize) == "5a2ed557c357ba8f96f2d55a8a00695987806b5df766cd1dfdab0cbed111774a" or
        hash.sha256(0, filesize) == "5e06af187b45476ade0d953e834fced6197d0a33ac60c2575877660e26ab15e8" or
        hash.sha256(0, filesize) == "65c1a998bac48e02b52b1c850cd500e9fb87521e21755c3a4a491243f5f9a700" or
        hash.sha256(0, filesize) == "6bc2e11b0917f47d0557288c4f0cb20bd7589185943b989a969fdc6d3704ee73" or
        hash.sha256(0, filesize) == "9d07a83cf89685651ea8992047ae694c24f6ddef193044357debd15ce07a64fe" or
        hash.sha256(0, filesize) == "9e81ade09cc18f0fc09d73e72d2e0bffad02f52fdcc26553e473cee8cabc1567" or
        hash.sha256(0, filesize) == "d4eb4ff02df659fdeec17d36b77084627469623bb3c7d16383d257404b52d1c3" or
        hash.sha256(0, filesize) == "e2f0c2d4c1552cd81fa012043e4a5ac832582b639b7b6b7eccc0c4802d7a8ad8" or
        hash.sha256(0, filesize) == "e6e78eb2e9bd41a4bc62f7ad54d095ea9813864bebe37172ae30a1afa631fe14" or
        hash.sha256(0, filesize) == "fadbb8061715128bebecf7bc59132b6bb04fe8cc39b965aa5b8722dffe28d7e7" or
        hash.sha256(0, filesize) == "ffb9eb47cc0cb2f43e04a10dc84df13d04bca1ebacbe47fad0b669728de2f59c"
}

rule BulwarkBlack_artoken_eviltokens_microsoft_365_bec_token_defense
{
    meta:
        description = "Indicators from Bulwark Black report: ARToken Shows Microsoft 365 Tokens Are the New BEC Control Plane"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/artoken-eviltokens-microsoft-365-bec-token-defense/"
        date = "2026-07-01"
        net_indicators = 12
        file_hashes = 0
    strings:
        $n0 = "clear90489058903-document.workers.dev" ascii wide nocase
        $n1 = "dashboard-bl.pamconj.com" ascii wide nocase
        $n2 = "mononapfp.sharepoint.com" ascii wide nocase
        $n3 = "mononapfpcom.sharepoint.com" ascii wide nocase
        $n4 = "sharepoint.com" ascii wide nocase
        $n5 = "spx.pamconj.com" ascii wide nocase
        $n6 = "https://mononapfp.sharepoint.com/:f:/document/INV-IgCx1X50pgUjR7iAjZL2fuQaAW4GfKVs6wHT3BYv9sgwW7g”" ascii wide nocase
        $n7 = "https://mononapfpcom.sharepoint.com/:f:/g/IgAdH_aaBPMcQbtINZzC1TsLARj3dHj63MnKjvnY-QJrKEc" ascii wide nocase
        $n8 = "pamconj.com" ascii wide nocase
        $n9 = "sharepoint.com/:f:/document/INV-IgCx1X50pgUjR7iAjZL2fuQaAW4GfKVs6wHT3BYv9sgwW7g”" ascii wide nocase
        $n10 = "sharepoint.com/:f:/g/IgAdH_aaBPMcQbtINZzC1TsLARj3dHj63MnKjvnY-QJrKEc" ascii wide nocase
        $n11 = "workers.dev" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_simplehelp_cve_2026_48558_taskweaver_djinn_stealer_defense
{
    meta:
        description = "Indicators from Bulwark Black report: SimpleHelp Exploitation Shows RMM Is a Credential Control Plane"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/simplehelp-cve-2026-48558-taskweaver-djinn-stealer-defense/"
        date = "2026-06-30"
        net_indicators = 7
        file_hashes = 0
    strings:
        $n0 = "blackpointcyber.com" ascii wide nocase
        $n1 = "horizon3.ai" ascii wide nocase
        $n2 = "simple-help.com" ascii wide nocase
        $n3 = "https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/" ascii wide nocase
        $n4 = "https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/" ascii wide nocase
        $n5 = "https://simple-help.com/release-news" ascii wide nocase
        $n6 = "https://simple-help.com/security/simplehelp-security-update-2026-05" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_bing_seo_poisoning_bumblebee_adaptix_akira_ransomware
{
    meta:
        description = "Indicators from Bulwark Black report: Bing SEO Poisoning Shows IT Admin Downloads Are Ransomware Initial Access"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/bing-seo-poisoning-bumblebee-adaptix-akira-ransomware/"
        date = "2026-06-30"
        net_indicators = 41
        file_hashes = 9
    strings:
        $n0 = "109.205.195.211" ascii wide
        $n1 = "170.130.55.223" ascii wide
        $n2 = "171.22.183.43" ascii wide
        $n3 = "172.96.137.160" ascii wide
        $n4 = "185.174.100.203" ascii wide
        $n5 = "188.40.187.145" ascii wide
        $n6 = "192.121.22.94" ascii wide
        $n7 = "193.242.184.150" ascii wide
        $n8 = "194.127.178.21" ascii wide
        $n9 = "4.239.95.1" ascii wide
        $n10 = "84.32.84.32" ascii wide
        $n11 = "2rxyt8yrhq0bgj.org" ascii wide nocase
        $n12 = "2rxyt9urhq0bgj.org" ascii wide nocase
        $n13 = "5ka8rxp6t6eup2.org" ascii wide nocase
        $n14 = "6cimu4mc085em8.org" ascii wide nocase
        $n15 = "8doj8uvx604eck.org" ascii wide nocase
        $n16 = "Tria.ge" ascii wide nocase
        $n17 = "certgraveyard.org" ascii wide nocase
        $n18 = "d1hmxkpwby0d4s.org" ascii wide nocase
        $n19 = "delete.me" ascii wide nocase
        $n20 = "download-center.online" ascii wide nocase
        $n21 = "download-server.online" ascii wide nocase
        $n22 = "ev2sirbd269o5j.org" ascii wide nocase
        $n23 = "ewujsfb1dp5ran.org" ascii wide nocase
        $n24 = "ip-scanner.org" ascii wide nocase
        $n25 = "ks501oz9nm3v05.org" ascii wide nocase
        $n26 = "kwywztxoo2xdot.org" ascii wide nocase
        $n27 = "ky1d1p1daahe5t.org" ascii wide nocase
        $n28 = "netml.shop" ascii wide nocase
        $n29 = "opmanager.pro" ascii wide nocase
        $n30 = "ovh1kn1tcqw5kp.org" ascii wide nocase
        $n31 = "shopping5.shop" ascii wide nocase
        $n32 = "sigmasearchengine.com" ascii wide nocase
        $n33 = "soft-hub.pro" ascii wide nocase
        $n34 = "soft-server.online" ascii wide nocase
        $n35 = "urlscan.io" ascii wide nocase
        $n36 = "v5rjsdqogstopr.org" ascii wide nocase
        $n37 = "yj6jurm5qqkye5.org" ascii wide nocase
        $n38 = "zenmap.pro" ascii wide nocase
        $n39 = "https://tria.ge/250530-ttmjhayzhw" ascii wide nocase
        $n40 = "https://tria.ge/250812-zw4tfszpy4" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "124a48b78060fa851e1cc077ca35713c" or
        hash.md5(0, filesize) == "8c113b3aa82c81eee7c6b4ed0ba9a90f" or
        hash.md5(0, filesize) == "ca8646dfc88423bb9fffda811160cebe" or
        hash.sha1(0, filesize) == "ab82bf27132323861810c0efcac6d5dd01600dd4" or
        hash.sha1(0, filesize) == "d66944e1a57daf04d3e809f22cd01946d593acaf" or
        hash.sha1(0, filesize) == "febbaf5f08a8e0782ffcce8beef1f2b4e249a52b" or
        hash.sha256(0, filesize) == "186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5da" or
        hash.sha256(0, filesize) == "a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331" or
        hash.sha256(0, filesize) == "de730d969854c3697fd0e0803826b4222f3a14efe47e4c60ed749fff6edce19d"
}

rule BulwarkBlack_shai_hulud_cicd_cloud_identity_redshift_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Shai Hulud Shows CI/CD Identity Is Production Cloud Identity"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/shai-hulud-cicd-cloud-identity-redshift-defense/"
        date = "2026-06-29"
        net_indicators = 4
        file_hashes = 0
    strings:
        $n0 = "185.204.1.225" ascii wide
        $n1 = "89.22.231.63" ascii wide
        $n2 = "0.0.0.0/0" ascii wide
        $n3 = "1.0.0.dev" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_ai_coding_agent_clean_repo_runtime_payload_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Clean Repos Can Still Burn Developer Machines When AI Agents Trust Runtime Setup"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/ai-coding-agent-clean-repo-runtime-payload-defense/"
        date = "2026-06-27"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "0din.ai" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_splunk_enterprise_cve_2026_20253_siem_tier_zero_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Splunk Enterprise RCE Shows SIEM Servers Are Tier-Zero Infrastructure"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/splunk-enterprise-cve-2026-20253-siem-tier-zero-defense/"
        date = "2026-06-27"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "attacker-db.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_hospitality_photo_zip_nodejs_implant_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Hospitality Photo-ZIP Campaign Shows Front Desk Workflows Are Initial Access Paths"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/hospitality-photo-zip-nodejs-implant-defense/"
        date = "2026-06-26"
        net_indicators = 70
        file_hashes = 22
    strings:
        $n0 = "172.67.161.215" ascii wide
        $n1 = "178.16.54.27" ascii wide
        $n2 = "178.16.55.179" ascii wide
        $n3 = "193.202.84.32" ascii wide
        $n4 = "208.95.112.1" ascii wide
        $n5 = "95.217.97.121" ascii wide
        $n6 = "aluminiostramuntana.com" ascii wide nocase
        $n7 = "bookreservphoto.pro" ascii wide nocase
        $n8 = "dancamp.info" ascii wide nocase
        $n9 = "dashgamein.info" ascii wide nocase
        $n10 = "deeprace.info" ascii wide nocase
        $n11 = "derbyoni.info" ascii wide nocase
        $n12 = "doc-imagehub.info" ascii wide nocase
        $n13 = "docshub-01.info" ascii wide nocase
        $n14 = "docshub-secure.com" ascii wide nocase
        $n15 = "docstore-safe.info" ascii wide nocase
        $n16 = "expedla-getphoto.cloud" ascii wide nocase
        $n17 = "fairyspells.info" ascii wide nocase
        $n18 = "finallyrain.info" ascii wide nocase
        $n19 = "hakeiwjs727wj.com" ascii wide nocase
        $n20 = "haobbao.com" ascii wide nocase
        $n21 = "heliosup.info" ascii wide nocase
        $n22 = "higoksbupwou.com" ascii wide nocase
        $n23 = "image-vlt.info" ascii wide nocase
        $n24 = "imagestore-hub.info" ascii wide nocase
        $n25 = "imagevault-safe.info" ascii wide nocase
        $n26 = "ip-api.com" ascii wide nocase
        $n27 = "joincroud.info" ascii wide nocase
        $n28 = "kellystreets.info" ascii wide nocase
        $n29 = "kelopins.info" ascii wide nocase
        $n30 = "kentjerk.info" ascii wide nocase
        $n31 = "keypmenu.info" ascii wide nocase
        $n32 = "kinghoruswe.info" ascii wide nocase
        $n33 = "kiptownim.info" ascii wide nocase
        $n34 = "lestresot.info" ascii wide nocase
        $n35 = "lookinlip.info" ascii wide nocase
        $n36 = "ministrew.info" ascii wide nocase
        $n37 = "montagelips.info" ascii wide nocase
        $n38 = "photo-21473.xyz" ascii wide nocase
        $n39 = "photo-box.info" ascii wide nocase
        $n40 = "photo-dekor.xyz" ascii wide nocase
        $n41 = "photo-hub-io.info" ascii wide nocase
        $n42 = "photobook-reserv.pro" ascii wide nocase
        $n43 = "photobookadm.pro" ascii wide nocase
        $n44 = "photodoc-secure.info" ascii wide nocase
        $n45 = "photosafe-hub.info" ascii wide nocase
        $n46 = "prejointl.info" ascii wide nocase
        $n47 = "racestrech.info" ascii wide nocase
        $n48 = "recallnine.info" ascii wide nocase
        $n49 = "recepyman.info" ascii wide nocase
        $n50 = "recstrace.info" ascii wide nocase
        $n51 = "reservebookphot.pro" ascii wide nocase
        $n52 = "safe-picvault.info" ascii wide nocase
        $n53 = "safedoc-storage.info" ascii wide nocase
        $n54 = "safedoc-vault.info" ascii wide nocase
        $n55 = "safedocphoto.info" ascii wide nocase
        $n56 = "safephoto-vault.info" ascii wide nocase
        $n57 = "safevault-hub.info" ascii wide nocase
        $n58 = "sec-safe-dc.info" ascii wide nocase
        $n59 = "secure-imagehub.info" ascii wide nocase
        $n60 = "snapkeep.info" ascii wide nocase
        $n61 = "tripadvisor-photo-view.com" ascii wide nocase
        $n62 = "vertualstreak.info" ascii wide nocase
        $n63 = "visa-safedocs.info" ascii wide nocase
        $n64 = "visa-vault.info" ascii wide nocase
        $n65 = "visaimage-storage.icu" ascii wide nocase
        $n66 = "visaimages.info" ascii wide nocase
        $n67 = "visaphoto-secure.info" ascii wide nocase
        $n68 = "visaphoto-vault.info" ascii wide nocase
        $n69 = "widjssij728dj.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "17082531775760189576112827972435" or
        hash.md5(0, filesize) == "25908558764390958596189327204542" or
        hash.sha256(0, filesize) == "04ec44f2618460f5c77c5e56014a512cc03a123c9c5b6b6b1273e2a1681ac2e1" or
        hash.sha256(0, filesize) == "06a2888c1f07119873ccb051221bd8717281494b33585f4242556e6e5e227969" or
        hash.sha256(0, filesize) == "1c693bcdaf1da636eb21c274b21cc2f6c52c62ddd514700783eee83fe13acb0a" or
        hash.sha256(0, filesize) == "1f8daffec5945a13a1e9231f4a76655d4c7ef4560d0c64ca3abfe48f38297cbd" or
        hash.sha256(0, filesize) == "2e5fd01b7949a45937b853eabcf4b03195614cf84338dcaaa97240d1c5301ddc" or
        hash.sha256(0, filesize) == "3f66634f103b80412d1d670b91befab2a74425d2ea76d904c4a7ffae2ae94b44" or
        hash.sha256(0, filesize) == "49cc0e0c3ec060fb354cacee244d4f297aaefb6db66e67a21262d6c4d2eae1bd" or
        hash.sha256(0, filesize) == "63565f15a99769bbcd527a4d53e5cc259d80e1254463ef9c878c2074685558ae" or
        hash.sha256(0, filesize) == "6580de3b74fd635a1d7a887b8f6e5b0c9ac9e90d6e20466ad41489203119cca9" or
        hash.sha256(0, filesize) == "83e970feb3f10692c164f6889f7a026f135c2433e5bf8e662a6e63a3b81267b7" or
        hash.sha256(0, filesize) == "89934cb1494cf0327f0ab82fe644c74caf687814379cad116bd7adaca74c1028" or
        hash.sha256(0, filesize) == "97448688b292bfec6d83b153588076fe59b111c35ac4e42a916238df16a71e2f" or
        hash.sha256(0, filesize) == "98825c0c7764f45c891275b2f038ea559e84b340df30b41c2cc77b8d4215c6c8" or
        hash.sha256(0, filesize) == "9f10e3b6e5745784f26d18c38ce01fba054b19749c17260978ac11472564aee2" or
        hash.sha256(0, filesize) == "b7f46b192cd83a1d2487cb048cca645f6e8855b9673d500d50bbdb04eebc6bea" or
        hash.sha256(0, filesize) == "bd6805782df15e53581096b99bd6bbb81f4d4a5e2d2b30954df63175a4075be9" or
        hash.sha256(0, filesize) == "c5baa0c16b0074a1e94b48aa0177e9bfc23746aca8a5b42848a6685da85658b5" or
        hash.sha256(0, filesize) == "d14ba95cdce1ef7dc9ad3ac74949ca5db38b27378ee30f30a23cf26f9e875a11" or
        hash.sha256(0, filesize) == "da4b72764ae929050353f3da759c839e2a061a8b9a8dd3c3b2e909d4a8a3291c" or
        hash.sha256(0, filesize) == "f629311734b7c6e6579f8e1d0e1e3f3bf72c9ac6c301b631ba4df7f393c41b14"
}

rule BulwarkBlack_cl_sta_1062_tinyrct_critical_infrastructure_web_shell_defense
{
    meta:
        description = "Indicators from Bulwark Black report: CL-STA-1062 Shows Critical Infrastructure Intrusions Still Start With Web Shells"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/cl-sta-1062-tinyrct-critical-infrastructure-web-shell-defense/"
        date = "2026-06-26"
        net_indicators = 11
        file_hashes = 6
    strings:
        $n0 = "139.180.134.221" ascii wide
        $n1 = "202.182.102.5" ascii wide
        $n2 = "45.32.113.172" ascii wide
        $n3 = "45.76.210.43" ascii wide
        $n4 = "http://139.180.134.221/PerfWatson2.exe" ascii wide nocase
        $n5 = "http://139.180.134.221/sdksdk608/1.zip" ascii wide nocase
        $n6 = "http://139.180.134.221/sdksdk608/anydesk%5f0117.zip" ascii wide nocase
        $n7 = "http://139.180.134.221/sdksdk608/hamcore.se2" ascii wide nocase
        $n8 = "http://139.180.134.221/sdksdk608/httpdf" ascii wide nocase
        $n9 = "http://139.180.134.221/sdksdk608/vpn%5fbridge.config" ascii wide nocase
        $n10 = "http://139.180.134.221/sdksdk608/win-vpn.rar" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "00e09754526d0fe836ba27e3144ae161b0ecd3774abec5560504a16a67f0087c" or
        hash.sha256(0, filesize) == "4e1f8888d020decd09799ec946f1bf677cac6612b24582ddbf4d8ede425d8384" or
        hash.sha256(0, filesize) == "9b481b69cd91b09fa7bae7428f646dd89473a4c03393e43da81fe756cde1c472" or
        hash.sha256(0, filesize) == "cbfe8de6ffadbb1d396f61e63eb18e8b11c29527c1528641e3223d4c516cf7c3" or
        hash.sha256(0, filesize) == "dce5df29bddff5a4ddaea5c4fec14da91f7b69063a6e1c45ed61e5da4fc6c87b" or
        hash.sha256(0, filesize) == "f34bd1d485de437fe18360d1e850c3fd64415e49d691e610711d8d232071a0b1"
}

rule BulwarkBlack_turla_stockstay_backdoor_egress_visibility
{
    meta:
        description = "Indicators from Bulwark Black report: Turla’s STOCKSTAY Backdoor Shows Why Espionage Defense Needs Egress Visibility"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/turla-stockstay-backdoor-egress-visibility/"
        date = "2026-06-25"
        net_indicators = 22
        file_hashes = 51
    strings:
        $n0 = "4.4.3.12" ascii wide
        $n1 = "basecon.com" ascii wide nocase
        $n2 = "basecon.com.ua" ascii wide nocase
        $n3 = "canal1zac1a.onrender.com" ascii wide nocase
        $n4 = "circoloesteri.elezioni.idnet.it" ascii wide nocase
        $n5 = "driverx86-adobe.onrender.com" ascii wide nocase
        $n6 = "google-ai-labs-it.onrender.com" ascii wide nocase
        $n7 = "online.zp.ua" ascii wide nocase
        $n8 = "stream.bybit.com" ascii wide nocase
        $n9 = "ukr.net" ascii wide nocase
        $n10 = "weatherdataai.theworkpc.com" ascii wide nocase
        $n11 = "wool-basalt-clock.glitch.me" ascii wide nocase
        $n12 = "ws-api.binance.com" ascii wide nocase
        $n13 = "ws-feed-public.sandbox.exchange.coinbase.com" ascii wide nocase
        $n14 = "ws-feed.exchange.coinbase.com" ascii wide nocase
        $n15 = "www.circoloesteri.it" ascii wide nocase
        $n16 = "www.drs.gov.ua" ascii wide nocase
        $n17 = "https://basecon.com.ua/calculator.rar" ascii wide nocase
        $n18 = "https://circoloesteri.elezioni.idnet.it/admin-election/riepilogo.php" ascii wide nocase
        $n19 = "https://online.zp.ua/wp-content/uploads/Tools/EditorToolsPdf.zip" ascii wide nocase
        $n20 = "https://www.circoloesteri.it/" ascii wide nocase
        $n21 = "https://www.drs.gov.ua/wp-content/themes/twentytwentyfive/docs.zip" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "0a545dd1b703cddfb3d582c8c70f65f556bbd580bfa836a387121eb837bda61b" or
        hash.sha256(0, filesize) == "0d6b083208097d5b3e189891338540f6c64faaaaf268b0bb0b085dd53d5857b4" or
        hash.sha256(0, filesize) == "1682e8d82016b3f10434d2ebac995fd3b6aa812f079bfd7888652e94a994d851" or
        hash.sha256(0, filesize) == "19e6ed42248f9d03beb343a7c09a864dcd3cd671c29e1e5eac93579225224ac9" or
        hash.sha256(0, filesize) == "1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011f" or
        hash.sha256(0, filesize) == "1fc23ec18a94a599a34c74ef5f49a1e27acd37a07d5846661702b5e7e81a6a24" or
        hash.sha256(0, filesize) == "249a4c7cacdd8e99a2a089a5c0ce904f2eff22e0e40fcfb10f7824dca6c51ecb" or
        hash.sha256(0, filesize) == "2623c6e3c1f5a7b5e735a64813bc0e1382ae45831f5fadffb08c0e7b096627f7" or
        hash.sha256(0, filesize) == "2af7b513c05e76d7da5f75bb0a223c894a706c99ef2c2ddfe4eae542f95a08e0" or
        hash.sha256(0, filesize) == "34fcbe7e90fc87a4f3766469c19a64f24672d7adb99e0198f5ba10d58911368b" or
        hash.sha256(0, filesize) == "3627f582420ad2782d452fe6d13fae42658d1484296351d3916703e25dcadd14" or
        hash.sha256(0, filesize) == "391e51354118fb87dc57650cbbd94258c3f7c0a0d6868040b7a473ad626ff25e" or
        hash.sha256(0, filesize) == "40a3b969d81ef1ef35dd9ebcc6774e060b1b8949d3d74f38ca6b7d789c95cdb3" or
        hash.sha256(0, filesize) == "40b1208dda0cd5dd95c6b57764b2cfe7145b3ed9457f498408b4aaa05bf3ef50" or
        hash.sha256(0, filesize) == "447f430b46fad5a3f8e8c5aad1f8f7f79af069489c3d9c29224bb9f14f0c7bf4" or
        hash.sha256(0, filesize) == "45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893" or
        hash.sha256(0, filesize) == "4e3bed10a8eff3e9205c1f37f647512464271d5ac65df7ae4709735621a38320" or
        hash.sha256(0, filesize) == "55249f296b63a8bcf911b8bc96de43c1ac2b4a56c150a19d33d892a47e57352c" or
        hash.sha256(0, filesize) == "626330d22f77d9cbca9d40cc06568041703f194610c4c5a84bbb05a2e4ee7459" or
        hash.sha256(0, filesize) == "6298f3150ad94a242e649886d47c59c634a4d04b9af5ee15e3bf335c40b5e58e" or
        hash.sha256(0, filesize) == "667a8f568a611f2f3d84a366b7946b360e055bece9699c95aad619637ab72a38" or
        hash.sha256(0, filesize) == "6cee9e838792ac5e2098362d68ce93a9a2c095d476dc16b289fe8509c99b2b8b" or
        hash.sha256(0, filesize) == "6da0b4c1a5d0d3fb6e6a2990a82ba51db1f68a3bba818baa46526a29731e2342" or
        hash.sha256(0, filesize) == "7615140f78d9a0ce31cc9fe8c54c60028a7439cb32526fd97b10afef7145dd78" or
        hash.sha256(0, filesize) == "77417df21b4b4e8d86b8bda4afeef93fd36f355362586b2d1f51121a82244167" or
        hash.sha256(0, filesize) == "80f6c010fd260d0bcf18a4b6a8d62505adbed50d2e615ed9522c4bfd61c00661" or
        hash.sha256(0, filesize) == "813c78b5b6ef28a9c0ed35f2c6cd88fc50880ab91f8777dfe7aaccb1c24b08d5" or
        hash.sha256(0, filesize) == "81aabf646619ea5f4a72457cd3aa17c5988003d67e6454f45e7cb33613021bac" or
        hash.sha256(0, filesize) == "82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb" or
        hash.sha256(0, filesize) == "9164054d0bf0b7c8820da4f742860940998984555e65820e4fa8dd07b6bd67ec" or
        hash.sha256(0, filesize) == "98ce3c6e4dd05887ea619f2bbfeb2e2c2805ed07e85e119b79b828b7ef8be397" or
        hash.sha256(0, filesize) == "9fe944147c15a87963b06baf6473288d64c23655a0ba9369c35566272d8efc73" or
        hash.sha256(0, filesize) == "a40bf9c75d1bfa6d66f1179f2321de6589f80d3089d992797a9cb0e84f6196ce" or
        hash.sha256(0, filesize) == "b064a3efb04ed77e6c57955089ce639e193d166c8ea2216c98c3e9b701ea2cff" or
        hash.sha256(0, filesize) == "b287347a5bff8af360ce0e6500c336b6fe6d97920abc26202c9d843ffebc5f89" or
        hash.sha256(0, filesize) == "b55f3b8a7334af049ba3f70a9ad3fe78574b1e180c68baf9a7110d104387a636" or
        hash.sha256(0, filesize) == "b728eba4f0d6d16602fbad05a591f14391594262d3584b2e249e97f86e4dcc5a" or
        hash.sha256(0, filesize) == "c905cb512018cc55512c6a22677c3d6f389c47afd54d7c85797868fc4fcb90e9" or
        hash.sha256(0, filesize) == "d1e54270433a94aa3d45d888e4c62299bee3480eb2cb4a5489c7dda69d476c3e" or
        hash.sha256(0, filesize) == "d3fd32f915c239872c9e7ed9408b1f36dfcef03aa68f9a396d05c437667cdb43" or
        hash.sha256(0, filesize) == "d8fe8f3fe838d5b1a1043096f6f6bb6f524f5f1b0c9f83a081078a824daa0cf3" or
        hash.sha256(0, filesize) == "da8a96bc74e265f945f1cc6992c6dc0f9ea36ed1991f7b8d312db79d9bf78c40" or
        hash.sha256(0, filesize) == "dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22" or
        hash.sha256(0, filesize) == "e1d16fb635060d23e889b0617d77f0cf06d00cc19b43a2c8b5ac53ac027ac722" or
        hash.sha256(0, filesize) == "e2a0f4440f67998a0215d49be31746ea192bfcb4dc4ee532a218f8cf13605714" or
        hash.sha256(0, filesize) == "e316b1e13154dc6115e1e0c023f6fe3d17861cae839d4a4a81779b6aad9a24f8" or
        hash.sha256(0, filesize) == "e3364ee21cae6725451e8bc9ab9933df0000fd19814170bd132da68d1906d5ff" or
        hash.sha256(0, filesize) == "e6d8192960a89d5480868b94088cccdaa1560f9c8a0b0282ced2b7c1f72341b6" or
        hash.sha256(0, filesize) == "e83f274bf9914c6cfc0c6b3cdadf089565f49dace4aca93287c22aba9641c8f3" or
        hash.sha256(0, filesize) == "f04f43b6f7c2d86109c495179b497f7fb45fd95816623de1b77900f71b4f99ed" or
        hash.sha256(0, filesize) == "f964353b9ae4bedbe62de6c0d7eafa9fb8b87897bbaea483aedaa8ae191834da"
}

rule BulwarkBlack_strikeshark_sharkloader_cobalt_strike_defense
{
    meta:
        description = "Indicators from Bulwark Black report: StrikeShark Shows Loader Malware Is an Edge-Exposure Problem"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/strikeshark-sharkloader-cobalt-strike-defense/"
        date = "2026-06-25"
        net_indicators = 4
        file_hashes = 9
    strings:
        $n0 = "connect-microsoft.com" ascii wide nocase
        $n1 = "ms-record.com" ascii wide nocase
        $n2 = "ms-record.top" ascii wide nocase
        $n3 = "ms-tray.top" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "1f65544978b8ea0e745e573b8ee9684b" or
        hash.md5(0, filesize) == "24fcebdeecba65004fdb0923763d74fd" or
        hash.md5(0, filesize) == "9c872a0d5d5a38950e8b9ac9b488be3f" or
        hash.md5(0, filesize) == "9cbd560f820c95d7c38342cd558cb5c6" or
        hash.md5(0, filesize) == "a514d1bb62d7916475946fe7c07ac0aa" or
        hash.md5(0, filesize) == "aa3086be652c8b20b0b29b2730d57119" or
        hash.md5(0, filesize) == "b3352b42432dedc4a519f011dc8b5d5a" or
        hash.md5(0, filesize) == "c559cc68986933200fd5d9e4388e2f58" or
        hash.md5(0, filesize) == "d98f568496512e4f98670c61c97cb07a"
}

rule BulwarkBlack_operation_escaneo_latin_america_edge_device_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Operation Escaneo Shows Latin America’s Edge Devices Are Prime Intrusion Targets"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/operation-escaneo-latin-america-edge-device-defense/"
        date = "2026-06-20"
        net_indicators = 12
        file_hashes = 0
    strings:
        $n0 = "135.237.122.202" ascii wide
        $n1 = "165.22.184.26" ascii wide
        $n2 = "185.65.245.10" ascii wide
        $n3 = "200.79.113.136" ascii wide
        $n4 = "201.144.122.58" ascii wide
        $n5 = "201.144.122.60" ascii wide
        $n6 = "45.61.137.126" ascii wide
        $n7 = "62.171.185.97" ascii wide
        $n8 = "ld-linux-x86-64.so" ascii wide nocase
        $n9 = "rev.sh" ascii wide nocase
        $n10 = "www.news9live.com" ascii wide nocase
        $n11 = "https://www.news9live.com/technology/tech-news/hackers-used-claude-hit-mexico-agencies-150gb-data-claim-report-2936314" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_showboat_linux_malware_telecom_persistence_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Showboat Malware Shows Telecom Linux Servers Need Rootkit-Level Monitoring"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/showboat-linux-malware-telecom-persistence-defense/"
        date = "2026-06-20"
        net_indicators = 6
        file_hashes = 0
    strings:
        $n0 = "ld.so" ascii wide nocase
        $n1 = "pastebin.com" ascii wide nocase
        $n2 = "telecom.webredirect.org" ascii wide nocase
        $n3 = "ukpkmkk.so" ascii wide nocase
        $n4 = "https://pastebin.com/raw/[actor_page" ascii wide nocase
        $n5 = "webredirect.org" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_autojack_ai_agent_localhost_rce_boundaries
{
    meta:
        description = "Indicators from Bulwark Black report: AutoJack Shows AI Browsing Agents Need Localhost Boundaries"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/autojack-ai-agent-localhost-rce-boundaries/"
        date = "2026-06-19"
        net_indicators = 3
        file_hashes = 0
    strings:
        $n0 = "evil.com" ascii wide nocase
        $n1 = "msft.net" ascii wide nocase
        $n2 = "https://evil.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_apache_apisix_auth_bypass_plugin_review
{
    meta:
        description = "Indicators from Bulwark Black report: Apache APISIX Auth Bypass Cluster Shows API Gateways Need Plugin-Level Review"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/apache-apisix-auth-bypass-plugin-review/"
        date = "2026-06-19"
        net_indicators = 4
        file_hashes = 0
    strings:
        $n0 = "apisix.apache.org" ascii wide nocase
        $n1 = "www.cve.org" ascii wide nocase
        $n2 = "https://apisix.apache.org" ascii wide nocase
        $n3 = "https://www.cve.org/CVERecord?id=CVE-2026-39999" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_uefi_secure_boot_bypass_dbx_revocation_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Vendor-Signed UEFI Apps Show Secure Boot Still Depends on Revocation Hygiene"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/uefi-secure-boot-bypass-dbx-revocation-defense/"
        date = "2026-06-18"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "pg.ae" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_smartapesg_okendo_widget_supply_chain_risk
{
    meta:
        description = "Indicators from Bulwark Black report: SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/smartapesg-okendo-widget-supply-chain-risk/"
        date = "2026-06-18"
        net_indicators = 12
        file_hashes = 0
    strings:
        $n0 = "api.wigetticks.com" ascii wide nocase
        $n1 = "api.wizzleticks.com" ascii wide nocase
        $n2 = "cdn-static.okendo.io" ascii wide nocase
        $n3 = "okendo.io" ascii wide nocase
        $n4 = "wigetticks.com" ascii wide nocase
        $n5 = "wizzleticks.com" ascii wide nocase
        $n6 = "api.wigetticks.com/logout/private-response[" ascii wide nocase
        $n7 = "api.wizzleticks.com/claims/scope-schema[" ascii wide nocase
        $n8 = "cdn-static.okendo.io/reviews-widget-plus/js/okendo-reviews[" ascii wide nocase
        $n9 = "http://cdn-static.okendo.io/reviews-widget-plus/js/okendo-reviews.js" ascii wide nocase
        $n10 = "https://api.wigetticks.com/logout/private-response.php?8D1V4th3" ascii wide nocase
        $n11 = "https://api.wizzleticks.com/claims/scope-schema.php?4ManBBdA" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_tor_crypto_clipper_usb_worm_backdoor_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Tor-Based Crypto Clipper Shows Clipboard Theft Is Now Backdoor Activity"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/tor-crypto-clipper-usb-worm-backdoor-defense/"
        date = "2026-06-18"
        net_indicators = 0
        file_hashes = 16
    condition:
        hash.sha256(0, filesize) == "0020d23b0f9c5e6851a7f737af73fd143175ee47054931166369edd93338538a" or
        hash.sha256(0, filesize) == "100407796028bf3649752d9d2a67a0e4394d752eb8de86daa42920e814f3fae8" or
        hash.sha256(0, filesize) == "20db98af3037b197c8a846dbf17b87fc6f049c3e0d9a188f9b9a74d3916dd5e1" or
        hash.sha256(0, filesize) == "23c1e673f315dafa14b73034a90dd3d393a984451ff6601b8be8142be6487b43" or
        hash.sha256(0, filesize) == "35a6bc44b176a050fd6824904b7604f0f45b0fdfa26bf9500b9e05973b387cfd" or
        hash.sha256(0, filesize) == "67fc5cf395e28294bbb91ed0e954fdf2e80ebd9119022a115a42c286dc8bacf5" or
        hash.sha256(0, filesize) == "7630debd35cac6b7d58c4427695579b3e3a8b1cc462f523234cd6c698882a68c" or
        hash.sha256(0, filesize) == "7787a9a7d8ae393aa32f257d083903c4dc9b97a1e5b0458c4cd480d4f3cb5b05" or
        hash.sha256(0, filesize) == "9d90f54ae36c6c5435d5b8bed40faf54cc91f6db28574a6310b5ffaeb0362e96" or
        hash.sha256(0, filesize) == "a7abf1d9d6686af1cefcd60b17a312e7eb8cfe267def1ec34aeab6128c811630" or
        hash.sha256(0, filesize) == "b2777b73a4c33ac6a409d475057843be6b5d32262ef28a1f1ff5bb52e3834c5f" or
        hash.sha256(0, filesize) == "c824630154ac4fdfce94ded01f037c305eab51e9bef3f493c60ff3184a640502" or
        hash.sha256(0, filesize) == "cf9fc891ea5ca5ecd8113ef3e69f6f52ff538b6cccbdaa9559106fc72bc6da30" or
        hash.sha256(0, filesize) == "d14b80cbd1a19d4ad0473a0661297f8fdf598e81ff6c4ab24e212dcad2e54b3f" or
        hash.sha256(0, filesize) == "d43bf94f0cb0ab97c88113b7e07d1a4024d1610617b5ad05882b1dbab89e15ba" or
        hash.sha256(0, filesize) == "f3b54984caca95fd496bcfe5d7db1611b08d2f5b7d250b43b430e5d76393f9e0"
}

rule BulwarkBlack_velvet_ant_operation_highland_authentication_stack_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Velvet Ant Shows Authentication Infrastructure Is Critical Infrastructure"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/velvet-ant-operation-highland-authentication-stack-defense/"
        date = "2026-06-13"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "libethscsi.so" ascii wide nocase
        $n1 = "thc.org" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_shai_hulud_ai_scanner_evasion_package_supply_chain_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Shai-Hulud Shows AI Package Scanners Need Prompt-Injection Boundaries"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/shai-hulud-ai-scanner-evasion-package-supply-chain-defense/"
        date = "2026-06-13"
        net_indicators = 7
        file_hashes = 3
    strings:
        $n0 = "anthropic.com" ascii wide nocase
        $n1 = "api.anthropic.com" ascii wide nocase
        $n2 = "fulcio.sigstore.dev" ascii wide nocase
        $n3 = "litellm.cloud" ascii wide nocase
        $n4 = "models.litellm.cloud" ascii wide nocase
        $n5 = "api.anthropic.com/v1/api" ascii wide nocase
        $n6 = "https://api.anthropic.com/v1/api" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "c539766062555d47716f8432e73adbe3a0c0c954a0b6c4005017a668975e275c" or
        hash.sha256(0, filesize) == "dc48b09b2a5954f7ff79ab8a2fd80202bd3b59c08c7cdbc6025aa923cb4c0efe" or
        hash.sha256(0, filesize) == "e1342a80d4b5e83d2c7c22e1e0aaa95f2d88e3dbf0d853a4994b180c93a4b17d"
}

rule BulwarkBlack_shinyhunters_peoplesoft_cve_2026_35273_erp_admin_endpoints
{
    meta:
        description = "Indicators from Bulwark Black report: ShinyHunters PeopleSoft Exploitation Shows ERP Admin Endpoints Are Breach Surface"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/shinyhunters-peoplesoft-cve-2026-35273-erp-admin-endpoints/"
        date = "2026-06-11"
        net_indicators = 7
        file_hashes = 5
    strings:
        $n0 = "142.11.200.186" ascii wide
        $n1 = "142.11.200.187" ascii wide
        $n2 = "142.11.200.188" ascii wide
        $n3 = "142.11.200.189" ascii wide
        $n4 = "142.11.200.190" ascii wide
        $n5 = "176.120.22.24" ascii wide
        $n6 = "azurenetfiles.net" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35" or
        hash.sha256(0, filesize) == "68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309" or
        hash.sha256(0, filesize) == "c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f" or
        hash.sha256(0, filesize) == "d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f" or
        hash.sha256(0, filesize) == "f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc"
}

rule BulwarkBlack_pink_extortion_m365_vishing_cloud_data_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Pink Extortion Shows Microsoft 365 Defense Starts With Vishing Controls"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/pink-extortion-m365-vishing-cloud-data-defense/"
        date = "2026-06-06"
        net_indicators = 6
        file_hashes = 0
    strings:
        $n0 = "172.93.100.252" ascii wide
        $n1 = "185.178.208.153" ascii wide
        $n2 = "96.232.20.66" ascii wide
        $n3 = "deploypasskey.com" ascii wide nocase
        $n4 = "passkeyadd.com" ascii wide nocase
        $n5 = "passkeydeploy.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_pan_os_globalprotect_cve_2026_0257_vpn_log_review
{
    meta:
        description = "Indicators from Bulwark Black report: PAN-OS GlobalProtect Exploitation Shows VPN Access Needs Log Review, Not Just Patching"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/pan-os-globalprotect-cve-2026-0257-vpn-log-review/"
        date = "2026-06-06"
        net_indicators = 9
        file_hashes = 0
    strings:
        $n0 = "104.207.144.154" ascii wide
        $n1 = "146.19.216.119" ascii wide
        $n2 = "146.19.216.120" ascii wide
        $n3 = "146.19.216.125" ascii wide
        $n4 = "179.43.172.213" ascii wide
        $n5 = "185.195.232.139" ascii wide
        $n6 = "198.12.106.60" ascii wide
        $n7 = "202.144.192.47" ascii wide
        $n8 = "23.128.228.6" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_unc3753_vishing_rmm_physical_intrusions_law_firms
{
    meta:
        description = "Indicators from Bulwark Black report: UNC3753 Brings Vishing, RMM Abuse, and Physical Intrusions to U.S. Law Firms"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/unc3753-vishing-rmm-physical-intrusions-law-firms/"
        date = "2026-06-05"
        net_indicators = 13
        file_hashes = 0
    strings:
        $n0 = "174.169.162.62" ascii wide
        $n1 = "192.236.146.173" ascii wide
        $n2 = "192.236.147.131" ascii wide
        $n3 = "192.236.147.138" ascii wide
        $n4 = "192.236.154.158" ascii wide
        $n5 = "193.141.60.212" ascii wide
        $n6 = "64.94.84.97" ascii wide
        $n7 = "business-data-leaks.com" ascii wide nocase
        $n8 = "privnote.com" ascii wide nocase
        $n9 = "helpdesk.com" ascii wide nocase
        $n10 = "https://business-data-leaks.com" ascii wide nocase
        $n11 = "it.com" ascii wide nocase
        $n12 = "itdesk.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_cisco_sdwan_cve_2026_20245_edge_controller_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Cisco SD-WAN Zero-Day Shows Edge Controllers Need Compromise Review"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/cisco-sdwan-cve-2026-20245-edge-controller-defense/"
        date = "2026-06-05"
        net_indicators = 11
        file_hashes = 0
    strings:
        $n0 = "20.12.7.1" ascii wide
        $n1 = "20.12.7.2" ascii wide
        $n2 = "20.15.4.4" ascii wide
        $n3 = "20.15.4.5" ascii wide
        $n4 = "20.15.5.2" ascii wide
        $n5 = "20.15.5.3" ascii wide
        $n6 = "20.18.3.1" ascii wide
        $n7 = "20.9.9.1" ascii wide
        $n8 = "20.9.9.2" ascii wide
        $n9 = "26.1.1.1" ascii wide
        $n10 = "26.1.1.2" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_error_524_smishing_fraud_infrastructure_cti_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Error 524 Smishing Shows Why Fraud Infrastructure Needs CTI"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/error-524-smishing-fraud-infrastructure-cti-defense/"
        date = "2026-06-04"
        net_indicators = 8
        file_hashes = 0
    strings:
        $n0 = "154.81.166.17" ascii wide
        $n1 = "43.159.168.186" ascii wide
        $n2 = "43.162.84.202" ascii wide
        $n3 = "43.165.6.36" ascii wide
        $n4 = "45.135.162.90" ascii wide
        $n5 = "47.82.154.2" ascii wide
        $n6 = "8.222.134.149" ascii wide
        $n7 = "ipapi.co" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_ta4922_global_hr_tax_phishing_rmm_defense
{
    meta:
        description = "Indicators from Bulwark Black report: TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/ta4922-global-hr-tax-phishing-rmm-defense/"
        date = "2026-06-03"
        net_indicators = 8
        file_hashes = 14
    strings:
        $n0 = "103.214.172.33" ascii wide
        $n1 = "154.211.86.110" ascii wide
        $n2 = "18.139.83.110" ascii wide
        $n3 = "206.238.115.58" ascii wide
        $n4 = "43.156.77.97" ascii wide
        $n5 = "aeya388.club" ascii wide nocase
        $n6 = "nwphotoblog.com" ascii wide nocase
        $n7 = "srt.tw" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "0857148fb0bc4aa7adf967ede2307bdb4fc427065d5b6a6db132688a5a8e1eb8" or
        hash.sha256(0, filesize) == "2d2a251a88632f010fd9671789746908eeccaa5bc5c0a5d25e4649efe4f5b15d" or
        hash.sha256(0, filesize) == "3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2d" or
        hash.sha256(0, filesize) == "314f4b59535d1b783e1c20c2be00f9e30f8ed27b2e21fad06a73b47ea43279ef" or
        hash.sha256(0, filesize) == "40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5" or
        hash.sha256(0, filesize) == "4fcfa88fffacbce30bbe2136753c9ab5a4c092940d2406fd9d44d5118e745b9d" or
        hash.sha256(0, filesize) == "584a9448dda46bd590d7a2f86228100d2ae6e0d6d990c1a4459ed5ee28e07ae8" or
        hash.sha256(0, filesize) == "66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60d" or
        hash.sha256(0, filesize) == "8c9b6542f73c5c7fe455b52f5101314407da4f65ff48e7ebf6896605e607c8d0" or
        hash.sha256(0, filesize) == "9d0a55c545c4147956db2c2667c4ed931a2875309147548b1dfdd216228f5f73" or
        hash.sha256(0, filesize) == "a648db354820ea4d02940cb1702b35974513b7aae83f6dffaacaac4ba31f9295" or
        hash.sha256(0, filesize) == "a75eab31d7ff06b6864960ad7e633be3f9730ff3d3873e4539c8f425fc632dad" or
        hash.sha256(0, filesize) == "de82998ad5fcd63deae030803388e0fb4290d6223fda82368fd25b99b823f0d2" or
        hash.sha256(0, filesize) == "e0a6a71c605d9a4076147e9537f82f79f1e1eccadc874595160aa4637ff4088c"
}

rule BulwarkBlack_red_hat_miasma_npm_supply_chain_trusted_publishing_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/red-hat-miasma-npm-supply-chain-trusted-publishing-defense/"
        date = "2026-06-03"
        net_indicators = 2
        file_hashes = 2
    strings:
        $n0 = "www.aikido.dev" ascii wide nocase
        $n1 = "https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha1(0, filesize) == "0c5077e51419868618aeaa5fe8019c62421857d6" or
        hash.sha1(0, filesize) == "de0fac2e4500dabe0009e67214ff5f5447ce83dd"
}

rule BulwarkBlack_flutterbridge_macos_malvertising_fluttershell_backdoor_defense
{
    meta:
        description = "Indicators from Bulwark Black report: FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/flutterbridge-macos-malvertising-fluttershell-backdoor-defense/"
        date = "2026-06-02"
        net_indicators = 22
        file_hashes = 9
    strings:
        $n0 = "PDF-Brain.app" ascii wide nocase
        $n1 = "PDF-Ninja.app" ascii wide nocase
        $n2 = "ads-parkpro.com" ascii wide nocase
        $n3 = "adsparkpro.net" ascii wide nocase
        $n4 = "adsparkpro.top" ascii wide nocase
        $n5 = "atsheisdomestic.org" ascii wide nocase
        $n6 = "com.app" ascii wide nocase
        $n7 = "com.pdfninja.app" ascii wide nocase
        $n8 = "dart.dev" ascii wide nocase
        $n9 = "etoftheappyrince.org" ascii wide nocase
        $n10 = "flutter.dev" ascii wide nocase
        $n11 = "healightejustb.org" ascii wide nocase
        $n12 = "sinterfumesco.com" ascii wide nocase
        $n13 = "sparkle-project.org" ascii wide nocase
        $n14 = "atsheisdomestic.org/update-thanks.html" ascii wide nocase
        $n15 = "etoftheappyrince.org/update-delay" ascii wide nocase
        $n16 = "healightejustb.org/checkupdateTO.js" ascii wide nocase
        $n17 = "https://atsheisdomestic.org/update-thanks.html" ascii wide nocase
        $n18 = "https://etoftheappyrince.org/update-delay" ascii wide nocase
        $n19 = "https://healightejustb.org/checkupdateTO.js" ascii wide nocase
        $n20 = "https://sinterfumesco.com/search?utn=[Tracking" ascii wide nocase
        $n21 = "sinterfumesco.com/search?utn=[Tracking" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "021666417de8b9972c179783fe60d4c4ad2d93224e3a0f16137065c960b1b845" or
        hash.sha256(0, filesize) == "30448686ec900d5213d74f08f0d2b7924c5336a29445b2a434aba8d8b19d7530" or
        hash.sha256(0, filesize) == "363923500ce942bf1a953e8a4e943fbf1fb1b5ed6e5d247964c345b3ad5bfc34" or
        hash.sha256(0, filesize) == "48047c34bbd57fe1e24bc538bc2ce9e0ac4c4eb48d3b0c195b414f0379dc0745" or
        hash.sha256(0, filesize) == "644fc49fa1006a2a2acace694e5fb83753164e2617051ece6d9dc9ea32329e70" or
        hash.sha256(0, filesize) == "8421c902364980e3d762ec6dbbe6b0f40577c27bd79b48c57d098328b2533109" or
        hash.sha256(0, filesize) == "9053e8ddaecca1f960c041c944ca8799fc71dc86a4b50d2639ee4e0d2cb82f47" or
        hash.sha256(0, filesize) == "9425e8e39fa8a7212cdd07f0917cb3dfde38a90b87297de2c82a5850aff1e4de" or
        hash.sha256(0, filesize) == "b60074d1ea2008a581f432f2dee5f84f78668d9dd8e66f75d03c42dabd89bdea"
}

rule BulwarkBlack_forticlient_ems_ekz_infostealer_delivery
{
    meta:
        description = "Indicators from Bulwark Black report: FortiClient EMS Exploitation Turns Endpoint Management Into an Infostealer Delivery System"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/forticlient-ems-ekz-infostealer-delivery/"
        date = "2026-06-02"
        net_indicators = 5
        file_hashes = 8
    strings:
        $n0 = "185.220.101.15" ascii wide
        $n1 = "192.42.116.14" ascii wide
        $n2 = "83.138.53.110" ascii wide
        $n3 = "http://83.138.53.110/dl/p.exe" ascii wide nocase
        $n4 = "http://83.138.53.110/service/save.php" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "338662fd0c4d750a0ba203a32b59f081" or
        hash.md5(0, filesize) == "8c5b72906e8183037532afc3f4639931" or
        hash.sha1(0, filesize) == "17e771c78430cc67e71d4547f8996a1a488e9d3f" or
        hash.sha256(0, filesize) == "0da123adf9251957a4b850a3f6bd6a753dd4892be176a84a18450e899534cc5e" or
        hash.sha256(0, filesize) == "2927bc31b4f8254c6b332fc03110a6373cad00ffa2ff9de427c26bb222017bb2" or
        hash.sha256(0, filesize) == "2f25ea1b622abf3212141af932c2ec4cbd6b2b5903c2a531121f691227d98cff" or
        hash.sha256(0, filesize) == "d91c00fad521e76efa89715cca89db487d5676f2c767c883482f9c8f82bd383a" or
        hash.sha256(0, filesize) == "fd65051c61a904a304919c04a8c8633c001183ac73ac461cd4d9057946f02bf5"
}

rule BulwarkBlack_meta_ai_support_bot_account_recovery_risk
{
    meta:
        description = "Indicators from Bulwark Black report: Meta AI Support Bot Abuse Shows Account Recovery Is Part of the Identity Perimeter"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/meta-ai-support-bot-account-recovery-risk/"
        date = "2026-06-01"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "thecybersecguru.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_solyximmortal_python_infostealer_business_risk
{
    meta:
        description = "Indicators from Bulwark Black report: SolyxImmortal Shows Why Python Infostealers Are a Business Risk, Not Just Malware Noise"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/solyximmortal-python-infostealer-business-risk/"
        date = "2026-06-01"
        net_indicators = 4
        file_hashes = 3
    strings:
        $n0 = "socprime.com" ascii wide nocase
        $n1 = "www.cyfirma.com" ascii wide nocase
        $n2 = "https://socprime.com/active-threats/solyximmortal-python-malware-analysis/" ascii wide nocase
        $n3 = "https://www.cyfirma.com/research/solyximmortal-python-malware-analysis/" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "2690f7c685784fff006fe451fa3b154c" or
        hash.sha1(0, filesize) == "81c66c043982cfee9e60ae94203f4336da0b50c0" or
        hash.sha256(0, filesize) == "5a1b440861ef652cc207158e7e129f0b3a22ed5ef5d2ea5968e1d9eff33017bc"
}

rule BulwarkBlack_showboat_jfmbackdoor_telecom_intrusion_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Showboat and JFMBackdoor Show Telecom Intrusions Are Built for Pivoting"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/showboat-jfmbackdoor-telecom-intrusion-defense/"
        date = "2026-06-01"
        net_indicators = 27
        file_hashes = 4
    strings:
        $n0 = "101.36.105.222" ascii wide
        $n1 = "116.169.244.208" ascii wide
        $n2 = "139.84.227.139" ascii wide
        $n3 = "192.9.141.111" ascii wide
        $n4 = "194.135.25.132" ascii wide
        $n5 = "23.27.201.160" ascii wide
        $n6 = "64.176.43.209" ascii wide
        $n7 = "assets.lumen.com" ascii wide nocase
        $n8 = "kaztelecom.shop" ascii wide nocase
        $n9 = "singtelcom.site" ascii wide nocase
        $n10 = "telecom.webredirect.org" ascii wide nocase
        $n11 = "webredirect.org" ascii wide nocase
        $n12 = "www.lumen.com" ascii wide nocase
        $n13 = "https://assets.lumen.com/is/content/Lumen/Black_Lotus_Labs_Video-6341053041112" ascii wide nocase
        $n14 = "https://assets.lumen.com/is/image/Lumen/author-black-lotus-labs-logo-image-300x300?Creativeid=b08a9660-2840-4cf8-b2b4-aa45b9585632" ascii wide nocase
        $n15 = "https://assets.lumen.com/is/image/Lumen/img-blog-bll-malware-fig1?$PNG$&#x26;Creativeid=baae57fe-30cb-446d-9373-b5835ed6d74a" ascii wide nocase
        $n16 = "https://assets.lumen.com/is/image/Lumen/img-blog-bll-malware-fig2?$PNG$&#x26;Creativeid=679e321b-7df3-45e4-9292-c1c02c13732c" ascii wide nocase
        $n17 = "https://assets.lumen.com/is/image/Lumen/img-blog-bll-malware-fig3?$PNG$&#x26;Creativeid=c742db12-86dc-4216-b182-07991ebadce5" ascii wide nocase
        $n18 = "https://assets.lumen.com/is/image/Lumen/img-blog-bll-malware-fig4?$PNG$&#x26;Creativeid=f104f1c6-3a1f-460b-b597-813b63e43e0d" ascii wide nocase
        $n19 = "https://assets.lumen.com/is/image/Lumen/img-blog-bll-malware-fig5?$PNG$&#x26;Creativeid=9f6a7f84-711d-4f83-b1b4-38b6129e1d23" ascii wide nocase
        $n20 = "https://assets.lumen.com/is/image/Lumen/img-blog-bll-malware-fig6?$PNG$&#x26;Creativeid=a9148deb-22b8-43c8-bb11-dc6feceb9714" ascii wide nocase
        $n21 = "https://assets.lumen.com/is/image/Lumen/img-blog-bll-malware-fig8?$PNG$&#x26;Creativeid=bdd1dcd8-5848-4020-b2e8-448ad48d9e98" ascii wide nocase
        $n22 = "https://assets.lumen.com/is/image/Lumen/img-blog-bll-malware-showboat-table?$JPG$&#x26;Creativeid=416e9156-1fd8-4382-b2a3-107f5062946a" ascii wide nocase
        $n23 = "https://assets.lumen.com/is/image/Lumen/img-blog-bll-newmalware-figure7?$PNG$&#x26;Creativeid=adbfea9c-c17b-4cbe-bb9d-c800b6b23a84" ascii wide nocase
        $n24 = "https://assets.lumen.com/is/image/Lumen/img-blog-featured-resource-card-bll?Creativeid=844b527d-b24a-4d66-928e-9d6964fc2220" ascii wide nocase
        $n25 = "https://assets.lumen.com/is/image/Lumen/img-blog-header-bll-malware-848x566?$PNG$&#x26;Creativeid=7832e142-117a-4b22-9ce4-cf575ba34f02" ascii wide nocase
        $n26 = "https://www.lumen.com/en-us/security/black-lotus-labs.html" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "2229e7f3cabbce4d67cd79c89fd5a100b20e8a99f4a2bf9aac77a978f49eb520" or
        hash.sha256(0, filesize) == "27df475626aafce2ea1548a9f35efb9ad951298c8b11a6adb3ccdfcd5170c677" or
        hash.sha256(0, filesize) == "a72427af3c046fd90999a6505b2372dc4ffde122227f30ed21621ecd4f2d3e8b" or
        hash.sha256(0, filesize) == "e28a96f983b8605decd2ac1db16ebad5fa741a6aa4e585a38ade0e5ad7d6cec0"
}

rule BulwarkBlack_mediainfolib_parser_bugs_file_metadata_execution_boundary
{
    meta:
        description = "Indicators from Bulwark Black report: MediaInfoLib Parser Bugs Show File Metadata Is an Execution Boundary"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/mediainfolib-parser-bugs-file-metadata-execution-boundary/"
        date = "2026-05-27"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "Snort.org" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_poisoned_search_ai_screenconnect_cryptojacking_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Poisoned Search and AI Recommendations Turn Utility Downloads Into RMM Access"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/poisoned-search-ai-screenconnect-cryptojacking-defense/"
        date = "2026-05-27"
        net_indicators = 14
        file_hashes = 12
    strings:
        $n0 = "193.42.11.108" ascii wide
        $n1 = "198.23.185.238" ascii wide
        $n2 = "2.59.132.106" ascii wide
        $n3 = "93.115.10.35" ascii wide
        $n4 = "Direct-download.giize.com" ascii wide nocase
        $n5 = "Free-download.giize.com" ascii wide nocase
        $n6 = "direct-download.gleeze.com" ascii wide nocase
        $n7 = "direct-downloads.giize.com" ascii wide nocase
        $n8 = "directdownload.icu" ascii wide nocase
        $n9 = "dynu.com" ascii wide nocase
        $n10 = "giize.com" ascii wide nocase
        $n11 = "gleeze.com" ascii wide nocase
        $n12 = "minemine.gleeze.com" ascii wide nocase
        $n13 = "start-download.gleeze.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "062bb28765fbaa11f8cc341fa16e2c7f942a122d929cb41f4a0f755b4429f246" or
        hash.sha256(0, filesize) == "16562974deec80e41ef57a71a6de8c03ceb393005fb1432f8d9d82c61294ef8c" or
        hash.sha256(0, filesize) == "1b2555b09ac62164638f47c8272beb6b0f97186e37d3a54cb84c723ff7a2eee5" or
        hash.sha256(0, filesize) == "2ee93ccbcd49ed94c65dcf52e7dcb8f0fa0a443ca24c0e0c7f79152efba657b7" or
        hash.sha256(0, filesize) == "69077fcf940fc5852fb32beed15636756ebc04ac971b7ed71d36251e7ea70a20" or
        hash.sha256(0, filesize) == "7035c2abeb617e828dfda1b119b8544fa9ae15a1d263d18bc5506acaf381f496" or
        hash.sha256(0, filesize) == "9ff07c9fafa9c03fdf69e4abf6806aa7c938b5480e7e258f227db0719ecd6386" or
        hash.sha256(0, filesize) == "a460d00ef93c8ce70d32e48e55781af66a53328fc2dde45519be196c265de074" or
        hash.sha256(0, filesize) == "c7425fbe6c3a4937934215c54027d4b67202d12ab490682fae03498870d66d06" or
        hash.sha256(0, filesize) == "cf3f8160eb5a5580e0c35054847e3ac4d01e9fe74fab8bc12bf6e8a40bf696b2" or
        hash.sha256(0, filesize) == "db2d33c4e6e4a5c2263b56e8303c343305a94dde1fc2968304ba260acbbd9f9f" or
        hash.sha256(0, filesize) == "e021662a652ba95c8778b991056696ab3c9b0f60d5e23b1e6cf73c3847db6610"
}

rule BulwarkBlack_megalodon_github_actions_cicd_secret_theft_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Megalodon GitHub Actions Backdoor Shows CI/CD Is Now a Credential Battlefield"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/megalodon-github-actions-cicd-secret-theft-defense/"
        date = "2026-05-26"
        net_indicators = 5
        file_hashes = 3
    strings:
        $n0 = "216.126.225.129" ascii wide
        $n1 = "safedep.io" ascii wide nocase
        $n2 = "teaak.com" ascii wide nocase
        $n3 = "http://216.126.225.129:8443" ascii wide nocase
        $n4 = "http://216.126.225.129:8443?h=megalodon&amp;l=gh_dump&amp;id=hefs8esnhgkx&quot" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha1(0, filesize) == "18aa49e5f42ceaf9f010f01a396f625100c7aad8" or
        hash.sha1(0, filesize) == "8a454e601c4f69576c4e4edd14b8d2a0c52eaf27" or
        hash.sha1(0, filesize) == "acac5a9854650c4ae2883c4740bf87d34120c038"
}

rule BulwarkBlack_knowledgedeliver_viewstate_shared_machine_key_defense
{
    meta:
        description = "Indicators from Bulwark Black report: KnowledgeDeliver RCE Shows Shared Machine Keys Are Shared Blast Radius"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/knowledgedeliver-viewstate-shared-machine-key-defense/"
        date = "2026-05-25"
        net_indicators = 2
        file_hashes = 1
    strings:
        $n0 = "121.0.0.0" ascii wide
        $n1 = "1.9.2.13" ascii wide
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "7c1f99dca8e5a7897892f9d224a6495023a2cfd2671697d229d355978c415ed2"
}

rule BulwarkBlack_laravel_lang_composer_supply_chain_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Laravel-Lang Compromise Shows Dependency Tags Can Be Weaponized"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/laravel-lang-composer-supply-chain-defense/"
        date = "2026-05-25"
        net_indicators = 3
        file_hashes = 0
    strings:
        $n0 = "Fly.io" ascii wide nocase
        $n1 = "flipboxstudio.info" ascii wide nocase
        $n2 = "flipboxstudio.info/exfil" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_clop_south_staffs_water_soc_coverage_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Cl0p’s South Staffs Water Case Shows SOC Coverage Must Be Proven"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/clop-south-staffs-water-soc-coverage-defense/"
        date = "2026-05-24"
        net_indicators = 16
        file_hashes = 0
    strings:
        $n0 = "Booking.com" ascii wide nocase
        $n1 = "decoded.avast.io" ascii wide nocase
        $n2 = "ico.org" ascii wide nocase
        $n3 = "ico.org.uk" ascii wide nocase
        $n4 = "malpedia.caad.fkie.fraunhofer.de" ascii wide nocase
        $n5 = "redcanary.com" ascii wide nocase
        $n6 = "securityintelligence.com" ascii wide nocase
        $n7 = "www.ransomware.live" ascii wide nocase
        $n8 = "https://decoded.avast.io/janvojtesek/raspberry-robins-roshtyak-a-little-lesson-in-trickery/" ascii wide nocase
        $n9 = "https://ico.org.uk/media2/xdrfahsw/south-staffordshire-plc-and-south-staffordshire-water-plc-monetary-penalty-notice.pdf" ascii wide nocase
        $n10 = "https://malpedia.caad.fkie.fraunhofer.de/details/win.clop" ascii wide nocase
        $n11 = "https://malpedia.caad.fkie.fraunhofer.de/details/win.get2" ascii wide nocase
        $n12 = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sdbbot" ascii wide nocase
        $n13 = "https://redcanary.com/blog/raspberry-robin" ascii wide nocase
        $n14 = "https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware/" ascii wide nocase
        $n15 = "https://www.ransomware.live/group/clop" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_roadtools_cloud_identity_entra_id_defense
{
    meta:
        description = "Indicators from Bulwark Black report: ROADtools Abuse Shows Cloud Identity Is the New Attack Surface"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/roadtools-cloud-identity-entra-id-defense/"
        date = "2026-05-24"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "enterpriseregistration.windows.net" ascii wide nocase
        $n1 = "windows.net" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_void_dokkaebi_invisibleferret_developer_endpoint_risk
{
    meta:
        description = "Indicators from Bulwark Black report: Void Dokkaebi’s InvisibleFerret Shift Shows Developer Endpoints Are Production Risk"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/void-dokkaebi-invisibleferret-developer-endpoint-risk/"
        date = "2026-05-23"
        net_indicators = 9
        file_hashes = 0
    strings:
        $n0 = "45.59.160.199" ascii wide
        $n1 = "brw.so" ascii wide nocase
        $n2 = "claude.ai" ascii wide nocase
        $n3 = "ip-api.com" ascii wide nocase
        $n4 = "mc.so" ascii wide nocase
        $n5 = "mod.so" ascii wide nocase
        $n6 = "pad.so" ascii wide nocase
        $n7 = "http://ip-api.com/json" ascii wide nocase
        $n8 = "ip-api.com/json" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_f5_confluence_edge_identity_attack_path
{
    meta:
        description = "Indicators from Bulwark Black report: F5-to-Confluence Intrusion Shows Edge Devices Are Identity Attack Paths"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/f5-confluence-edge-identity-attack-path/"
        date = "2026-05-22"
        net_indicators = 6
        file_hashes = 5
    strings:
        $n0 = "206.189.27.39" ascii wide
        $n1 = "my.f5.com" ascii wide nocase
        $n2 = "www.darktrace.com" ascii wide nocase
        $n3 = "http://206.189.27.39:8888/5" ascii wide nocase
        $n4 = "https://my.f5.com/manage/s/article/K000156741" ascii wide nocase
        $n5 = "https://www.darktrace.com/blog/darktraces-view-on-operation-lunar-peek-exploitation-of-palo-alto-firewall-devices-cve-2024-2012-and-2024-9474" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "4a927d031919fd6bd88d3c8a917214b54bca00f8ddc80ecfe4d230663dda7465" or
        hash.sha256(0, filesize) == "57b3188e24782c27fdf72493ce599537efd3187d03b80f8afe733c72d68c5517" or
        hash.sha256(0, filesize) == "710a9d2653c8bd3689e451778dab9daec0de4c4c75f900788ccf23ef254b122a" or
        hash.sha256(0, filesize) == "b4592cea69699b2c0737d4e19cff7dca17b5baf5a238cd6da950a37e9986f216" or
        hash.sha256(0, filesize) == "bdd5da81ac34d9faa2a5118d4ed8f492239734be02146cd24a0e34270a48a455"
}

rule BulwarkBlack_screening_serpens_recruiting_espionage_attack_surface
{
    meta:
        description = "Indicators from Bulwark Black report: Screening Serpens Shows Recruiting Is Now an Espionage Attack Surface"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/screening-serpens-recruiting-espionage-attack-surface/"
        date = "2026-05-22"
        net_indicators = 36
        file_hashes = 13
    strings:
        $n0 = "144.0.0.0" ascii wide
        $n1 = "146.0.0.0" ascii wide
        $n2 = "2117.filemail.com" ascii wide nocase
        $n3 = "Buisness-centeral-transportation.com" ascii wide nocase
        $n4 = "Businessstartup.azurewebsites.net" ascii wide nocase
        $n5 = "ElementShift.azurewebsites.net" ascii wide nocase
        $n6 = "LicenceSupporting.azurewebsites.net" ascii wide nocase
        $n7 = "NanoMatrix.azurewebsites.net" ascii wide nocase
        $n8 = "PeerDistSvcManagers.azurewebsites.net" ascii wide nocase
        $n9 = "Premier-HealthAdvisory.azurewebsites.net" ascii wide nocase
        $n10 = "PremierHealthAdvisory.azurewebsites.net" ascii wide nocase
        $n11 = "PremierHealthAdvisory.com" ascii wide nocase
        $n12 = "QuantumWeave.azurewebsites.net" ascii wide nocase
        $n13 = "Ramiltons-finance.azurewebsites.net" ascii wide nocase
        $n14 = "Ramiltonsfinance.azurewebsites.net" ascii wide nocase
        $n15 = "Ramiltonsfinance.com" ascii wide nocase
        $n16 = "ThemesManagers.azurewebsites.net" ascii wide nocase
        $n17 = "ThemesProviderManagers.azurewebsites.net" ascii wide nocase
        $n18 = "buisness-centeral-transportation.azurewebsites.net" ascii wide nocase
        $n19 = "buisness-centeral.azurewebsites.net" ascii wide nocase
        $n20 = "business-startup.azurewebsites.net" ascii wide nocase
        $n21 = "business-startup.org" ascii wide nocase
        $n22 = "docspace-twpf0e.onlyoffice.com" ascii wide nocase
        $n23 = "docspace-y4cumb.onlyoffice.com" ascii wide nocase
        $n24 = "licencemanagers.azurewebsites.net" ascii wide nocase
        $n25 = "azurewebsites.net" ascii wide nocase
        $n26 = "filemail.com/api/file/get?filekey=T0EnWQ6NugHkW_kLfDxPBEw_um6NSkg9ZwNRQ_5lrKrLLUo35pV8m3TKv1LqF3zZzdUm" ascii wide nocase
        $n27 = "https://2117.filemail.com/api/file/get?filekey=T0EnWQ6NugHkW_kLfDxPBEw_um6NSkg9ZwNRQ_5lrKrLLUo35pV8m3TKv1LqF3zZzdUm" ascii wide nocase
        $n28 = "https://ElementShift.azurewebsites.net" ascii wide nocase
        $n29 = "https://NanoMatrix.azurewebsites.net" ascii wide nocase
        $n30 = "https://QuantumWeave.azurewebsites.net" ascii wide nocase
        $n31 = "https://docspace-twpf0e.onlyoffice.com/storage/files/root/folder_3765000/file_3764519/v1/content.zip?filename=remote.[REDACTED].zip" ascii wide nocase
        $n32 = "https://docspace-y4cumb.onlyoffice.com/storage/files/root/folder_3602000/file_3601577/v1/content.zip[" ascii wide nocase
        $n33 = "onlyoffice.com" ascii wide nocase
        $n34 = "onlyoffice.com/storage/files/root/folder_3602000/file_3601577/v1/content.zip[" ascii wide nocase
        $n35 = "onlyoffice.com/storage/files/root/folder_3765000/file_3764519/v1/content.zip?filename=remote.[REDACTED" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "edcdba624ddb43c2a1dcf334aa493068" or
        hash.sha256(0, filesize) == "0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864" or
        hash.sha256(0, filesize) == "332ba2f0297dfb1599adecc3e9067893e7cf243aa23aedce4906a4c480574c17" or
        hash.sha256(0, filesize) == "38bd137c672bd58d08c4f0502f993a6561e2c3411773d1ae57ee0151a0a9d11d" or
        hash.sha256(0, filesize) == "43dc62cef52ebdd69e79f10015b3e13890f26c058325c0ff139c70f8d8eadcfa" or
        hash.sha256(0, filesize) == "44f4f7aca7f1d9bfdaf7b3736934cbe19f851a707662f8f0b0c49b383e054250" or
        hash.sha256(0, filesize) == "74882085db2088356ed7f72f01e0404a0a98cda88ef56fb15ce74c1f36b26d27" or
        hash.sha256(0, filesize) == "8808c794c24367438f183e4be941876f1d3ecd0c8d2eb43b10d2380841d2283b" or
        hash.sha256(0, filesize) == "9cf029daca89523d917dafed0568d11d00e45ec96b5b90b4a1f7fd4018c7da84" or
        hash.sha256(0, filesize) == "9e4a658e6d831c9e9bdfe11884a75b7c64812ed0a80e8495ddf6b316505acac1" or
        hash.sha256(0, filesize) == "b19e06da580cf91691eda066ac9ee4b09c6e5dc26c367af12660fe1f9306eec4" or
        hash.sha256(0, filesize) == "bc3b44154518c5794ce639108e7b9c5fecb0c189607a26de1aaed518d890c7ad" or
        hash.sha256(0, filesize) == "d4a7e9f107fe40c1a5d0139c6c6e25bf6bf57f61feff090bee28f476bb3cc3c2"
}

rule BulwarkBlack_kimwolf_arrest_iot_ddos_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Kimwolf Arrest Shows DDoS Risk Starts on Forgotten IoT"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/kimwolf-arrest-iot-ddos-defense/"
        date = "2026-05-22"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "ottawacitizen.com" ascii wide nocase
        $n1 = "https://ottawacitizen.com/news/local-news/what-is-going-on-in-ottawa-handcuffing-of-another-child-with-autism-worries-advocates" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_tamperedchef_signed_productivity_apps_malware_defense
{
    meta:
        description = "Indicators from Bulwark Black report: TamperedChef Shows Signed Productivity Apps Cannot Be Trusted by Default"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/tamperedchef-signed-productivity-apps-malware-defense/"
        date = "2026-05-21"
        net_indicators = 4
        file_hashes = 2
    strings:
        $n0 = "onezipapp.com" ascii wide nocase
        $n1 = "www.crystalpdf.com" ascii wide nocase
        $n2 = "crystalpdf.com/conditions" ascii wide nocase
        $n3 = "https://www.crystalpdf.com/conditions" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "2231bfa7c7bd4a8ff12568074f83de8e4ec95c226230cccc6616a1a4416de268" or
        hash.sha256(0, filesize) == "248de1470771904462c91f146074e49b3d7416844ec143ade53f4ac0487fdb44"
}

rule BulwarkBlack_patriot_bait_ai_enabled_fraud_trust_attack_surface
{
    meta:
        description = "Indicators from Bulwark Black report: Patriot Bait Shows AI-Enabled Fraud Can Turn Trust Into Attack Surface"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/patriot-bait-ai-enabled-fraud-trust-attack-surface/"
        date = "2026-05-21"
        net_indicators = 7
        file_hashes = 0
    strings:
        $n0 = "213.165.51.115" ascii wide
        $n1 = "34.34.57.141" ascii wide
        $n2 = "34.34.81.129" ascii wide
        $n3 = "35.192.41.201" ascii wide
        $n4 = "Venice.ai" ascii wide nocase
        $n5 = "claude.ai" ascii wide nocase
        $n6 = "vebrf.digital" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_p2pinfect_kubernetes_redis_botnet_defense
{
    meta:
        description = "Indicators from Bulwark Black report: P2Pinfect Shows Exposed Redis in Kubernetes Can Become Dormant Botnet Infrastructure"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/p2pinfect-kubernetes-redis-botnet-defense/"
        date = "2026-05-20"
        net_indicators = 8
        file_hashes = 4
    strings:
        $n0 = "178.62.63.125" ascii wide
        $n1 = "47.237.140.12" ascii wide
        $n2 = "47.83.124.121" ascii wide
        $n3 = "47.86.33.195" ascii wide
        $n4 = "47.86.5.176" ascii wide
        $n5 = "8.210.178.40" ascii wide
        $n6 = "8.210.50.65" ascii wide
        $n7 = "http://8.210.50.65:60126/linux" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "08ad2c2877edda9a050b81d011c1c003" or
        hash.md5(0, filesize) == "5d1ca537c4bedebf2f4d276d4199ea95" or
        hash.md5(0, filesize) == "80676a539765a9e117f20b6b99887eca" or
        hash.md5(0, filesize) == "a1a35afebb585917675534de3d610c93"
}

rule BulwarkBlack_fox_tempest_code_signing_trust_weaponized
{
    meta:
        description = "Indicators from Bulwark Black report: Fox Tempest Shows Code Signing Trust Can Be Weaponized"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/fox-tempest-code-signing-trust-weaponized/"
        date = "2026-05-19"
        net_indicators = 1
        file_hashes = 5
    strings:
        $n0 = "signspace.cloud" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha1(0, filesize) == "7e6d9dac619c04ae1b3c8c0906123e752ed66d63" or
        hash.sha1(0, filesize) == "dc0acb01e3086ea8a9cb144a5f97810d291020ce" or
        hash.sha256(0, filesize) == "11af4566539ad3224e968194c7a9ad7b596460d8f6e423fc62d1ea5fc0724326" or
        hash.sha256(0, filesize) == "f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc" or
        hash.sha256(0, filesize) == "f0a6b89ec7eee83274cd484cea526b970a3ef28038799b0a5774bb33c5793b55"
}

rule BulwarkBlack_storm_2949_cloud_identity_breach_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Storm-2949 Shows Cloud Breaches Start With Identity, Not Malware"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/storm-2949-cloud-identity-breach-defense/"
        date = "2026-05-19"
        net_indicators = 3
        file_hashes = 0
    strings:
        $n0 = "176.123.4.44" ascii wide
        $n1 = "185.241.208.243" ascii wide
        $n2 = "91.208.197.87" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_ai_agent_governance_security_control
{
    meta:
        description = "Indicators from Bulwark Black report: AI Agent Governance Is Becoming a Security Control, Not a Nice-to-Have"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/ai-agent-governance-security-control/"
        date = "2026-05-18"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "claude.ai" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_grafana_github_token_breach_source_code_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Grafana GitHub Token Breach Shows Why Source Code Access Needs Guardrails"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/grafana-github-token-breach-source-code-defense/"
        date = "2026-05-17"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "Ransomware.live" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_node_ipc_npm_supply_chain_ci_secrets_defense
{
    meta:
        description = "Indicators from Bulwark Black report: node-ipc Backdoor Shows Why CI Secrets Need Supply Chain Controls"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/node-ipc-npm-supply-chain-ci-secrets-defense/"
        date = "2026-05-17"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "sh.azurestaticprovider.net" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_device_code_phishing_oauth_token_theft_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Device Code Phishing Turns Legitimate Login Flows Into Token Theft"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/device-code-phishing-oauth-token-theft-defense/"
        date = "2026-05-16"
        net_indicators = 46
        file_hashes = 0
    strings:
        $n0 = "019d442a-endpoint.com" ascii wide nocase
        $n1 = "019d442e-endpoint.com" ascii wide nocase
        $n2 = "019d6860-endpoint.com" ascii wide nocase
        $n3 = "0fdba029e6a5-endpoint.com" ascii wide nocase
        $n4 = "2dc62559e005-endpoint.com" ascii wide nocase
        $n5 = "4daa2aea93db-endpoint.com" ascii wide nocase
        $n6 = "6dd5fd945b34-endpoint.com" ascii wide nocase
        $n7 = "7740f766-8d1d-46ad-a6bc-onedrive.p-9jluifuu.workers.dev" ascii wide nocase
        $n8 = "7806d4cf9366-endpoint.com" ascii wide nocase
        $n9 = "audit-report-9767d3.fullerjp09.workers.dev" ascii wide nocase
        $n10 = "consistentdigital.de" ascii wide nocase
        $n11 = "crediblebizextension.de" ascii wide nocase
        $n12 = "digitalcontinuity.de" ascii wide nocase
        $n13 = "digitalreliability.de" ascii wide nocase
        $n14 = "ed5ce47d835f-endpoint.com" ascii wide nocase
        $n15 = "ee10bbf6c689-endpoint.com" ascii wide nocase
        $n16 = "euromarketsignal.de" ascii wide nocase
        $n17 = "europesignaltrust.de" ascii wide nocase
        $n18 = "europetrustwave.de" ascii wide nocase
        $n19 = "extendyourcredibility.de" ascii wide nocase
        $n20 = "f36c2774f013-endpoint.com" ascii wide nocase
        $n21 = "f8uh-dwam-j4l5.pvasquez-princetonpartners-com-s-account.workers.dev" ascii wide nocase
        $n22 = "heilbronner-fruehlingssymposium.de" ascii wide nocase
        $n23 = "hewktree.net" ascii wide nocase
        $n24 = "hs-sites-na2.com" ascii wide nocase
        $n25 = "hti-245401512.hs-sites-na2.com" ascii wide nocase
        $n26 = "jo2c9ada427c6-endpoint.com" ascii wide nocase
        $n27 = "kohlhoff-edelstahlverarbeitung.de" ascii wide nocase
        $n28 = "marketcredibilitysignals.de" ascii wide nocase
        $n29 = "marktkarree-langenfeld.de" ascii wide nocase
        $n30 = "methodicalness.de" ascii wide nocase
        $n31 = "onedrive-7tu.techroboticslabmade-techie-com-s-account.workers.dev" ascii wide nocase
        $n32 = "panel.hewktree.net" ascii wide nocase
        $n33 = "reliableinteractions.de" ascii wide nocase
        $n34 = "reliablesupport.de" ascii wide nocase
        $n35 = "servicewithoutinterruption.de" ascii wide nocase
        $n36 = "stablewebsystems.de" ascii wide nocase
        $n37 = "trustedengagement.de" ascii wide nocase
        $n38 = "uninterruptedperformance.de" ascii wide nocase
        $n39 = "voicemail-59f.admin-treyripple-com-s-account.workers.dev" ascii wide nocase
        $n40 = "voicemail-lyr.nbuckley-cambek-com-s-account.workers.dev" ascii wide nocase
        $n41 = "voicemail-wx7.mark-squires-expressrancnes-com-s-account.workers.dev" ascii wide nocase
        $n42 = "workers.dev" ascii wide nocase
        $n43 = "yaga9b286ae2c101-endpoint.com" ascii wide nocase
        $n44 = "ytgw-9n30-xlwd.pvasquez-princetonpartners-com-s-account.workers.dev" ascii wide nocase
        $n45 = "z6e43e5886fe-endpoint.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_linux_kernel_ipsec_attack_surface_reduction
{
    meta:
        description = "Indicators from Bulwark Black report: Recent Linux Kernel Exploits Make Attack Surface Reduction a Practical Priority"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/linux-kernel-ipsec-attack-surface-reduction/"
        date = "2026-05-16"
        net_indicators = 4
        file_hashes = 0
    strings:
        $n0 = "badkeys.info" ascii wide nocase
        $n1 = "itsec.hboeck.de" ascii wide nocase
        $n2 = "https://badkeys.info/" ascii wide nocase
        $n3 = "https://itsec.hboeck.de/" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_pawsrunner_steganography_purelogs_infostealer_defense
{
    meta:
        description = "Indicators from Bulwark Black report: PawsRunner Steganography Shows Infostealers Are Hiding in Plain Sight"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/pawsrunner-steganography-purelogs-infostealer-defense/"
        date = "2026-05-16"
        net_indicators = 5
        file_hashes = 6
    strings:
        $n0 = "5.101.84.202" ascii wide
        $n1 = "everycarebd.com" ascii wide nocase
        $n2 = "xverse.app" ascii wide nocase
        $n3 = "everycarebd.com/imagelkjh0987[" ascii wide nocase
        $n4 = "https://everycarebd.com/imagelkjh0987.png" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "0fcb86ae384e9975933314ac2a231f0ff46c0208556bf4a16f096a642d3f505e" or
        hash.sha256(0, filesize) == "1b730de72f921458b6b162b105a9521a931f07e19d3cac53207c7a8efbc412f9" or
        hash.sha256(0, filesize) == "6910d27b9e1dc2229a8c280f5d0cea85146d50274c56a4d9a5b8d1793505b1b9" or
        hash.sha256(0, filesize) == "8d0bcde739929fe41a6bcaaa62f7cba802af90b2ba8dea6ed1a4821236cdd588" or
        hash.sha256(0, filesize) == "93724f1a9ad3a28c171927fc449ac34dc6ca890f915f00210e8b305577388c6e" or
        hash.sha256(0, filesize) == "e2308749f6b7b7573009d0cac6616a6aa83cecb1f2933e868776400d122c86ec"
}

rule BulwarkBlack_blackfile_vishing_extortion_identity_defense
{
    meta:
        description = "Indicators from Bulwark Black report: BlackFile Vishing Campaign Shows Why MFA Alone Is Not Enough"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/blackfile-vishing-extortion-identity-defense/"
        date = "2026-05-15"
        net_indicators = 9
        file_hashes = 0
    strings:
        $n0 = "179.43.185.226" ascii wide
        $n1 = "company.sharepoint.com" ascii wide nocase
        $n2 = "getsession.org" ascii wide nocase
        $n3 = "organization.sharepoint.com" ascii wide nocase
        $n4 = "enrollms.com" ascii wide nocase
        $n5 = "https://company.sharepoint.com/sites/ProductionOps/" ascii wide nocase
        $n6 = "https://organization.sharepoint.com/sites/Legal_Archive/" ascii wide nocase
        $n7 = "passkeyms.com" ascii wide nocase
        $n8 = "setupsso.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_gremlin_stealer_browser_session_resource_obfuscation
{
    meta:
        description = "Indicators from Bulwark Black report: Gremlin Stealer Shows Why Browser Sessions Are Now High-Value Targets"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/gremlin-stealer-browser-session-resource-obfuscation/"
        date = "2026-05-15"
        net_indicators = 7
        file_hashes = 11
    strings:
        $n0 = "194.87.92.109" ascii wide
        $n1 = "api.ipify.org" ascii wide nocase
        $n2 = "api.telegram.org" ascii wide nocase
        $n3 = "telegram.org" ascii wide nocase
        $n4 = "http://api.ipify.org/?format=json" ascii wide nocase
        $n5 = "https://api.telegram.org" ascii wide nocase
        $n6 = "ipify.org" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "1bd0a200528c82c6488b4f48dd6dbc818d48782a2e25ccd22781c5718c3f62f5" or
        hash.sha256(0, filesize) == "2172dae9a5a695e00e0e4609e7db0207d8566d225f7e815fada246ae995c0f9b" or
        hash.sha256(0, filesize) == "281b970f281dbea3c0e8cfc68b2e9939b253e5d3de52265b454d8f0f578768a2" or
        hash.sha256(0, filesize) == "691896c7be87e47f3e9ae914d76caaf026aaad0a1034e9f396c2354245215dc3" or
        hash.sha256(0, filesize) == "971198ff86aeb42739ba9381923d0bc6f847a91553ec57ea6bae5becf80f8759" or
        hash.sha256(0, filesize) == "9aab30a3190301016c79f8a7f8edf45ec088ceecad39926cfcf3418145f3d614" or
        hash.sha256(0, filesize) == "9fda1ddb1acf8dd3685ec31b0b07110855832e3bed28a0f3b81c57fe7fe3ac20" or
        hash.sha256(0, filesize) == "a9f529a5cbc1f3ee80f785b22e0c472953e6cb226952218aecc7ab07ca328abd" or
        hash.sha256(0, filesize) == "ab0fa760bd037a95c4dee431e649e0db860f7cdad6428895b9a399b6991bf3cd" or
        hash.sha256(0, filesize) == "d11938f14499de03d6a02b5e158782afd903460576e9227e0a15d960a2e9c02c" or
        hash.sha256(0, filesize) == "f76ba1a4650d8cafb6d3ff071688c5db6fd37e165050f03cece693826f51d346"
}

rule BulwarkBlack_cisco_sdwan_active_exploitation_edge_controller_review
{
    meta:
        description = "Indicators from Bulwark Black report: Cisco SD-WAN Exploitation Shows Edge Controllers Need Emergency Review"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/cisco-sdwan-active-exploitation-edge-controller-review/"
        date = "2026-05-15"
        net_indicators = 24
        file_hashes = 13
    strings:
        $n0 = "104.233.156.1" ascii wide
        $n1 = "13.62.52.206" ascii wide
        $n2 = "176.65.139.31" ascii wide
        $n3 = "194.163.175.135" ascii wide
        $n4 = "194.233.100.40" ascii wide
        $n5 = "212.83.162.37" ascii wide
        $n6 = "23.27.143.170" ascii wide
        $n7 = "38.181.52.89" ascii wide
        $n8 = "38.60.214.92" ascii wide
        $n9 = "47.104.248.7" ascii wide
        $n10 = "65.20.67.134" ascii wide
        $n11 = "71.80.85.135" ascii wide
        $n12 = "79.135.105.208" ascii wide
        $n13 = "83.229.126.195" ascii wide
        $n14 = "89.125.244.33" ascii wide
        $n15 = "89.125.244.51" ascii wide
        $n16 = "1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev" ascii wide nocase
        $n17 = "a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev" ascii wide nocase
        $n18 = "replit.dev" ascii wide nocase
        $n19 = "http://13.62.52.206:5004&nbsp" ascii wide nocase
        $n20 = "http://13.62.52.206:5004”" ascii wide nocase
        $n21 = "http://83.229.126.195:8081/config.json" ascii wide nocase
        $n22 = "http://83.229.126.195:8081/xmrig" ascii wide nocase
        $n23 = "https://1a820b09-95ba-44eb-b350-417e8241b725-00-1lgwuuen9b77p.worf.replit.dev/download" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "fece5b954e69b2c6a8d0a1029631a0d7" or
        hash.sha256(0, filesize) == "02654acfb21f83485393ba8b14bd8862b919b9ec966fc6768f6aac1338a45ee8" or
        hash.sha256(0, filesize) == "0c87871642f84e09e8d3fb23ec36bf55601323e31151a7017a85dbec929cf15d" or
        hash.sha256(0, filesize) == "0ed72d52347bfe4a78afff8a6982a64050c8fc86d8957a20eeb3e0f3f5342ed0" or
        hash.sha256(0, filesize) == "17302d903baf182f94dc3be40ab1e0874dd0eb2ec5255bf9131fd53591efe925" or
        hash.sha256(0, filesize) == "18d77c9c5bbb5b9d5bdfd366fdfcf26bad9e64c63ca865fad711bcce8e3d5a80" or
        hash.sha256(0, filesize) == "5bc5998161056b7c8f70c9724d8a63abc7ff8c3843b91c30cffab0899e39b7f8" or
        hash.sha256(0, filesize) == "72f570ce97de3eaaffef33d90b0c337a153fc9690cc34ee207b557d868360060" or
        hash.sha256(0, filesize) == "7aa88a64a527ade7d93c20faf23b54f2ee33ad9b1246cdc2f8ded2ab639affb1" or
        hash.sha256(0, filesize) == "96fc528ca5e7d1c2b3add5e31b8797cb126f704976c8fbeaecdbf0aa4309ad46" or
        hash.sha256(0, filesize) == "b0f51b098842cd630097b462aab0ec357e2c7824af37cca6d08165265da2c2d3" or
        hash.sha256(0, filesize) == "d94f75a70b5cabaf786ac57177ed841732e62bdcc9a29e06e5b41d9be567bcfa" or
        hash.sha256(0, filesize) == "f6f8e0d790645395188fc521039385b7c4f42fa8b426fd035f489f6cda9b5da1"
}

rule BulwarkBlack_kazuar_p2p_botnet_russian_espionage_defense
{
    meta:
        description = "Indicators from Bulwark Black report: Kazuar Shows Russian Espionage Malware Is Engineering for Resilience"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/kazuar-p2p-botnet-russian-espionage-defense/"
        date = "2026-05-14"
        net_indicators = 0
        file_hashes = 5
    condition:
        hash.md5(0, filesize) == "82760b84f1d703d596c79b88ba4fac1e" or
        hash.sha256(0, filesize) == "436cfce71290c2fc2f2c362541db68ced6847c66a73b55487e5e5c73b0636c85" or
        hash.sha256(0, filesize) == "69908f05b436bd97baae56296bf9b9e734486516f9bb9938c2b8752e152315d4" or
        hash.sha256(0, filesize) == "6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d" or
        hash.sha256(0, filesize) == "c1f278f88275e07cc03bd390fe1cbeedd55933110c6fd16de4187f4c4aaf42b9"
}

rule BulwarkBlack_gentlemen_raas_leak_edge_device_ransomware_risk
{
    meta:
        description = "Indicators from Bulwark Black report: The Gentlemen RaaS Leak Shows Ransomware Is Still an Edge-Device Problem"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/gentlemen-raas-leak-edge-device-ransomware-risk/"
        date = "2026-05-13"
        net_indicators = 1
        file_hashes = 63
    strings:
        $n0 = "chamd5.org" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "03860d116701cdc9d9bf9c45099bb3d3" or
        hash.md5(0, filesize) == "11e7baca7e652995b2364fdab0d362b7" or
        hash.md5(0, filesize) == "2cd4eb358c45ca783a20ec854a5a860c" or
        hash.md5(0, filesize) == "2e5d1a352885a6efd84dbc0387cbc79e" or
        hash.md5(0, filesize) == "3b7b4f2d33bdfb8a31b480d0eb2815cd" or
        hash.md5(0, filesize) == "4a94d2b730a5a63e6cd54a9b0bb4ea71" or
        hash.md5(0, filesize) == "4e0c37cbf4dde9683943c8a738e5b00a" or
        hash.md5(0, filesize) == "51dec3e170f8a181cc9aea8dcc90c7ab" or
        hash.md5(0, filesize) == "583fe1c1a39f6b873a5c0997bea1f657" or
        hash.md5(0, filesize) == "697f182826495662427ca49edbb345fc" or
        hash.md5(0, filesize) == "71d503709af88821c183a1d0b7ae06ec" or
        hash.md5(0, filesize) == "721606b3659f2c2d80a196ed3cd60053" or
        hash.md5(0, filesize) == "735069890a414869f0113de820ba9afb" or
        hash.md5(0, filesize) == "74ea100b581ec32ea6c2ac2a0030a9f6" or
        hash.md5(0, filesize) == "776e86c13433747299a4e5f9f22e3415" or
        hash.md5(0, filesize) == "7aae8fd9187c88dd0292cce1abd050e2" or
        hash.md5(0, filesize) == "81a578e065da1ccd8c81a8e90c309275" or
        hash.md5(0, filesize) == "82160a7da5fc4c935e6f48d38a5aaaa6" or
        hash.md5(0, filesize) == "893f735e9a8cc9814dc6eccd5579561c" or
        hash.md5(0, filesize) == "8fceea4fd9ce32dd620ccd580297c7c5" or
        hash.md5(0, filesize) == "92d8bd2a6ee7f6d5c84e037066ce0539" or
        hash.md5(0, filesize) == "a023a6b15419600dc3f6b93e11761dfe" or
        hash.md5(0, filesize) == "a73526d89e5fb7b57f50d8da340e53e9" or
        hash.md5(0, filesize) == "abd11823ddcc3d746ad8621e677a93eb" or
        hash.md5(0, filesize) == "b5b42ac289581b3387ebf120129a19a6" or
        hash.md5(0, filesize) == "b68e019efb39b85f5a0326e22fd4498a" or
        hash.md5(0, filesize) == "bc6b87c79bc71a78da623d031ec1a958" or
        hash.md5(0, filesize) == "d75246d230f22b1da6bbf5fceeed2ef2" or
        hash.md5(0, filesize) == "da9cff1b478b64d47b68d50330e96c60" or
        hash.md5(0, filesize) == "ead0d7a8ae0a6ffb7f0a5873fec4ff5e" or
        hash.sha256(0, filesize) == "025fc0976c548fb5a880c83ea3eb21a5f23c5d53c4e51e862bb893c11adf712a" or
        hash.sha256(0, filesize) == "1334f0189a8e6dbc48456fa4b482c5726ab7609f7fa652fcc4c1a96f2334436f" or
        hash.sha256(0, filesize) == "1af419b36a5edefef387409e2b3248c9223f7dc49a4f7b15ea095d371c3a70b2" or
        hash.sha256(0, filesize) == "1eece1e1ba4b96e6c784729f0608ad2939cfb67bc4236dfababbe1d09268960c" or
        hash.sha256(0, filesize) == "22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67" or
        hash.sha256(0, filesize) == "24ac3588fb8cfbff63b7fdfcbc7dec1f3c60e54e6f949dd69d68e89e0c89d966" or
        hash.sha256(0, filesize) == "2ed9494e9b7b68415b4eb151c922c82c0191294d0aa443dd2cb5133e6bfe3d5d" or
        hash.sha256(0, filesize) == "3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235" or
        hash.sha256(0, filesize) == "3c2182cb0bc7528829ef03f1b1745a92bcc47d917eb8870862488f21fdf1a6d6" or
        hash.sha256(0, filesize) == "48d9b2ce4fcd6854a3164ce395d7140014e0b58b77680623f3e4ca22d3a6e7fd" or
        hash.sha256(0, filesize) == "4a175eed927c0a477eafb8aa35a93c191748acaa78ac7aecd8ea3c4cd868887c" or
        hash.sha256(0, filesize) == "51b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2" or
        hash.sha256(0, filesize) == "5dc607c8990841139768884b1b43e1403496d5a458788a1937be139594f01dca" or
        hash.sha256(0, filesize) == "62c2c24937d67fdeb43f2c9690ab10e8bb90713af46945048db9a94a465ffcb8" or
        hash.sha256(0, filesize) == "6a3ab9e984a759d55af4e84487d1fc44683065cc9a1089d5aa4ad1c0e4e84a63" or
        hash.sha256(0, filesize) == "788ba200f776a188c248d6c2029f00b5d34be45d4444f7cb89ffe838c39b8b19" or
        hash.sha256(0, filesize) == "860a6177b055a2f5aa61470d17ec3c69da24f1cdf0a782237055cba431158923" or
        hash.sha256(0, filesize) == "87d25d0e5880b3b5cd30106853cbfc6ef1ad38966b30d9bd5b99df46098e546c" or
        hash.sha256(0, filesize) == "8aa0cb69ca2777001e0f4ba0eaab0841592710e4cc5ccd6b0b526d78bbd8bfba" or
        hash.sha256(0, filesize) == "8c87134c1b45e990e9568f0a3899b0076f94be16d3c40fa824ac1e6c6ee892db" or
        hash.sha256(0, filesize) == "91415e0b9fe4e7cbe43ec0558a7adf89423de30d22b00b985c2e4b97e75076b1" or
        hash.sha256(0, filesize) == "994d6d1edb57f945f4284cc0163ec998861c7496d85f6d45c08657c9727186e3" or
        hash.sha256(0, filesize) == "9f61ff4deb8afced8b1ecdc8787a134c63bde632b18293fbfc94a91749e3e454" or
        hash.sha256(0, filesize) == "a7a19cab7aab606f833fa8225bc94ec9570a6666660b02cc41a63fe39ea8b0ad" or
        hash.sha256(0, filesize) == "b67958afc982cafbe1c3f114b444d7f4c91a88a3e7a86f89ab8795ac2110d1e6" or
        hash.sha256(0, filesize) == "c46b5a18ab3fb5fd1c5c8288a41c75bf0170c10b5e829af89370a12c86dd10f8" or
        hash.sha256(0, filesize) == "c7f7b5a6e7d93221344e6368c7ab4abf93e162f7567e1a7bcb8786cb8a183a73" or
        hash.sha256(0, filesize) == "dce2e5cc00eff2493f8ced546dc51f9d5ef78c5ee56805906ec642dfa77a1c70" or
        hash.sha256(0, filesize) == "dfe696ff713318c53fb17731bd4a6585a02c085b590149b19847990b324a0be6" or
        hash.sha256(0, filesize) == "ec368ae0b4369b6ef0da244774995c819c63cffb7fd2132379963b9c1640ccd2" or
        hash.sha256(0, filesize) == "efaf8e7422ffd09c7f03f1a5b4e5c2cc32b05334c18d1ccb9673667f8f43108f" or
        hash.sha256(0, filesize) == "f736be55193c77af346dbe905e25f6a1dee3ec1aedca8989ad2088e4f6576b12" or
        hash.sha256(0, filesize) == "fc75ed2159e0c8274076e46a37671cfb8d677af9f586224da1713df89490a958"
}

rule BulwarkBlack_jdownloader_site_compromise_trusted_download_verification
{
    meta:
        description = "Indicators from Bulwark Black report: JDownloader Site Compromise Shows Why Trusted Downloads Still Need Verification"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/jdownloader-site-compromise-trusted-download-verification/"
        date = "2026-05-09"
        net_indicators = 7
        file_hashes = 0
    strings:
        $n0 = "auraguest.lk" ascii wide nocase
        $n1 = "checkinnhotels.com" ascii wide nocase
        $n2 = "parkspringshotel.com" ascii wide nocase
        $n3 = "auraguest.lk/m/douV2quu.php" ascii wide nocase
        $n4 = "https://auraguest.lk/m/douV2quu.php" ascii wide nocase
        $n5 = "https://parkspringshotel.com/m/Lu6aeloo.php" ascii wide nocase
        $n6 = "parkspringshotel.com/m/Lu6aeloo.php" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_fake_openai_hugging_face_infostealer_ai_supply_chain_risk
{
    meta:
        description = "Indicators from Bulwark Black report: Fake OpenAI Hugging Face Repo Shows AI Supply Chain Risk Is Already Here"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/fake-openai-hugging-face-infostealer-ai-supply-chain-risk/"
        date = "2026-05-09"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "recargapopular.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_mcp_server_command_injection_ai_tool_isolation
{
    meta:
        description = "Indicators from Bulwark Black report: MCP Server Command Injection Shows Why AI Tools Need Real Isolation"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/mcp-server-command-injection-ai-tool-isolation/"
        date = "2026-05-09"
        net_indicators = 0
        file_hashes = 1
    condition:
        hash.sha1(0, filesize) == "2e8ea913573610667ad54e31dba2e8198ebf7cf9"
}

rule BulwarkBlack_prompt_injection_rce_ai_agent_frameworks
{
    meta:
        description = "Indicators from Bulwark Black report: Prompt Injection Just Became an RCE Problem for AI Agents"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/prompt-injection-rce-ai-agent-frameworks/"
        date = "2026-05-08"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "param.name" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_pan_os_captive_portal_zero_day_edge_device_review
{
    meta:
        description = "Indicators from Bulwark Black report: PAN-OS Captive Portal Zero-Day Shows Why Internet-Facing Edge Devices Need Immediate Review"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/pan-os-captive-portal-zero-day-edge-device-review/"
        date = "2026-05-08"
        net_indicators = 6
        file_hashes = 1
    strings:
        $n0 = "136.0.8.48" ascii wide
        $n1 = "138.0.0.0" ascii wide
        $n2 = "146.70.100.69" ascii wide
        $n3 = "149.104.66.84" ascii wide
        $n4 = "67.206.213.86" ascii wide
        $n5 = "http://146.70.100.69:8000/php_sess" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584"
}

rule BulwarkBlack_cl_sta_1087_chinese_apt_targets_southeast_asian_militaries_with_applechris_and_memfun_backdoors
{
    meta:
        description = "Indicators from Bulwark Black report: CL-STA-1087: Chinese APT Targets Southeast Asian Militaries with AppleChris and MemFun Backdoors"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/cl-sta-1087-chinese-apt-targets-southeast-asian-militaries-with-applechris-and-memfun-backdoors/"
        date = "2026-04-03"
        net_indicators = 9
        file_hashes = 7
    strings:
        $n0 = "109.248.24.177" ascii wide
        $n1 = "116.63.177.49" ascii wide
        $n2 = "118.194.238.51" ascii wide
        $n3 = "154.39.137.203" ascii wide
        $n4 = "154.39.142.177" ascii wide
        $n5 = "8.212.169.27" ascii wide
        $n6 = "8.220.135.151" ascii wide
        $n7 = "8.220.177.252" ascii wide
        $n8 = "8.220.184.177" ascii wide
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "0e255b4b04f5064ff97da214050da81a823b3d99bce60cdd9ee90d913cc4a952" or
        hash.sha256(0, filesize) == "2ee667c0ddd4aa341adf8d85b54fbb2fce8cc14aa88967a5cb99babb08a10fae" or
        hash.sha256(0, filesize) == "413daa580db74a38397d09979090b291f916f0bb26a68e7e0b03b4390c1b472f" or
        hash.sha256(0, filesize) == "5a6ba08efcef32f5f38df544c319d1983adc35f3db64f77fa5b51b44d0e5052c" or
        hash.sha256(0, filesize) == "9e44a460196cc92fa6c6c8a12d74fb73a55955045733719e3966a7b8ced6c500" or
        hash.sha256(0, filesize) == "ad25b40315dad0bda5916854e1925c1514f8f8b94e4ee09a43375cc1e77422ad" or
        hash.sha256(0, filesize) == "ee4d4b7340b3fa70387050cd139b43ecc65d0cfd9e3c7dcb94562f5c9c91f58f"
}

rule BulwarkBlack_uat_10608_nexus_listener_framework_compromises_766_next_js_hosts_in_24_hour_credential_harvestin
{
    meta:
        description = "Indicators from Bulwark Black report: UAT-10608: NEXUS Listener Framework Compromises 766 Next.js Hosts in 24-Hour Credential Harvesting Blitz"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/uat-10608-nexus-listener-framework-compromises-766-next-js-hosts-in-24-hour-credential-harvesting-blitz/"
        date = "2026-04-03"
        net_indicators = 4
        file_hashes = 0
    strings:
        $n0 = "144.172.102.88" ascii wide
        $n1 = "144.172.112.136" ascii wide
        $n2 = "144.172.117.112" ascii wide
        $n3 = "172.86.127.128" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_litellm_supply_chain_attack_teampcp_deploys_multi_stage_credential_stealer_to_95m_monthly_downlo
{
    meta:
        description = "Indicators from Bulwark Black report: LiteLLM Supply Chain Attack: TeamPCP Deploys Multi-Stage Credential Stealer to 95M Monthly Downloads"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/litellm-supply-chain-attack-teampcp-deploys-multi-stage-credential-stealer-to-95m-monthly-downloads/"
        date = "2026-04-02"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "litellm.cloud" ascii wide nocase
        $n1 = "models.litellm.cloud" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_operation_truechaos_chinese_apt_exploits_trueconf_zero_day_cve_2026_3502_to_target_southeast_asi
{
    meta:
        description = "Indicators from Bulwark Black report: Operation TrueChaos: Chinese APT Exploits TrueConf Zero-Day CVE-2026-3502 to Target Southeast Asian Governments"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/operation-truechaos-chinese-apt-exploits-trueconf-zero-day-cve-2026-3502-to-target-southeast-asian-governments/"
        date = "2026-04-01"
        net_indicators = 6
        file_hashes = 3
    strings:
        $n0 = "43.134.52.221" ascii wide
        $n1 = "43.134.90.60" ascii wide
        $n2 = "47.237.15.197" ascii wide
        $n3 = "trueconf.com" ascii wide nocase
        $n4 = "ftp://47.237.15.197/update.7z" ascii wide nocase
        $n5 = "https://trueconf.com/docs/server/en/admin/info/" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "22e32bcf113326e366ac480b077067cf" or
        hash.md5(0, filesize) == "248a4d7d4c48478dcbeade8f7dba80b3" or
        hash.md5(0, filesize) == "9b435ad985b733b64a6d5f39080f4ae0"
}

rule BulwarkBlack_axios_npm_supply_chain_attack_deploys_cross_platform_rat_to_83_million_weekly_users
{
    meta:
        description = "Indicators from Bulwark Black report: Axios npm Supply Chain Attack Deploys Cross-Platform RAT to 83 Million Weekly Users"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/axios-npm-supply-chain-attack-deploys-cross-platform-rat-to-83-million-weekly-users/"
        date = "2026-04-01"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "packages.npm.org" ascii wide nocase
        $n1 = "sfrclak.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_deepload_malware_ai_generated_evasion_meets_clickfix_delivery_in_enterprise_credential_theft_cam
{
    meta:
        description = "Indicators from Bulwark Black report: DeepLoad Malware: AI-Generated Evasion Meets ClickFix Delivery in Enterprise Credential Theft Campaign"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/deepload-malware-ai-generated-evasion-meets-clickfix-delivery-in-enterprise-credential-theft-campaign/"
        date = "2026-03-31"
        net_indicators = 3
        file_hashes = 0
    strings:
        $n0 = "forest-entity.cc" ascii wide nocase
        $n1 = "hell1-kitty.cc" ascii wide nocase
        $n2 = "holiday-updateservice.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_shinyhunters_breaches_european_commission_350gb_of_sensitive_data_exfiltrated_from_aws_cloud
{
    meta:
        description = "Indicators from Bulwark Black report: ShinyHunters Breaches European Commission: 350GB of Sensitive Data Exfiltrated from AWS Cloud"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/shinyhunters-breaches-european-commission-350gb-of-sensitive-data-exfiltrated-from-aws-cloud/"
        date = "2026-03-31"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "Match.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_infinity_stealer_new_macos_infostealer_combines_clickfix_social_engineering_with_nuitka_compilat
{
    meta:
        description = "Indicators from Bulwark Black report: Infinity Stealer: New macOS Infostealer Combines ClickFix Social Engineering with Nuitka Compilation"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/infinity-stealer-new-macos-infostealer-combines-clickfix-social-engineering-with-nuitka-compilation/"
        date = "2026-03-29"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "update-check.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_infinity_stealer_new_macos_infostealer_uses_clickfix_and_nuitka_compilation_to_evade_detection
{
    meta:
        description = "Indicators from Bulwark Black report: Infinity Stealer: New macOS Infostealer Uses ClickFix and Nuitka Compilation to Evade Detection"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/infinity-stealer-new-macos-infostealer-uses-clickfix-and-nuitka-compilation-to-evade-detection/"
        date = "2026-03-29"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "update-check.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_infinity_stealer_new_macos_malware_uses_clickfix_lures_and_nuitka_compiled_python_payload
{
    meta:
        description = "Indicators from Bulwark Black report: Infinity Stealer: New macOS Malware Uses ClickFix Lures and Nuitka-Compiled Python Payload"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/infinity-stealer-new-macos-malware-uses-clickfix-lures-and-nuitka-compiled-python-payload/"
        date = "2026-03-28"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "update-check.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_pawn_storm_deploys_prismex_malware_suite_against_ukrainian_defense_supply_chain_and_nato_allies
{
    meta:
        description = "Indicators from Bulwark Black report: Pawn Storm Deploys PRISMEX Malware Suite Against Ukrainian Defense Supply Chain and NATO Allies"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/pawn-storm-deploys-prismex-malware-suite-against-ukrainian-defense-supply-chain-and-nato-allies/"
        date = "2026-03-26"
        net_indicators = 10
        file_hashes = 1
    strings:
        $n0 = "Filen.io" ascii wide nocase
        $n1 = "claude.ai" ascii wide nocase
        $n2 = "dropbox.com" ascii wide nocase
        $n3 = "egest.filen.io" ascii wide nocase
        $n4 = "gateway.filen-1.net" ascii wide nocase
        $n5 = "gateway.filen-6.net" ascii wide nocase
        $n6 = "gateway.filen.io" ascii wide nocase
        $n7 = "gateway.filen.net" ascii wide nocase
        $n8 = "ingest.filen.io" ascii wide nocase
        $n9 = "wellnesscaremed.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "aefd15e3c395edd16ede7685c6e97ca0350a702ee7c8585274b457166e86b1fa"
}

rule BulwarkBlack_oracle_issues_rare_out_of_band_patch_for_critical_cve_2026_21992_rce_in_identity_manager
{
    meta:
        description = "Indicators from Bulwark Black report: Oracle Issues Rare Out-of-Band Patch for Critical CVE-2026-21992 RCE in Identity Manager"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/oracle-issues-rare-out-of-band-patch-for-critical-cve-2026-21992-rce-in-identity-manager/"
        date = "2026-03-25"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "12.2.1.4" ascii wide
        $n1 = "14.1.2.1" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_canisterworm_wiper_weaponizes_trivy_supply_chain_to_target_iran
{
    meta:
        description = "Indicators from Bulwark Black report: CanisterWorm Wiper Weaponizes Trivy Supply Chain to Target Iran"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/canisterworm-wiper-weaponizes-trivy-supply-chain-to-target-iran/"
        date = "2026-03-24"
        net_indicators = 20
        file_hashes = 0
    strings:
        $n0 = "championships-peoples-point-cassette.trycloudflare.com" ascii wide nocase
        $n1 = "dl.k8s.io" ascii wide nocase
        $n2 = "icp0.io" ascii wide nocase
        $n3 = "investigation-launches-hearings-copying.trycloudflare.com" ascii wide nocase
        $n4 = "souls-entire-defined-routes.trycloudflare.com" ascii wide nocase
        $n5 = "tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io" ascii wide nocase
        $n6 = "trycloudflare.com" ascii wide nocase
        $n7 = "www.aikido.dev" ascii wide nocase
        $n8 = "https://championships-peoples-point-cassette.trycloudflare.com" ascii wide nocase
        $n9 = "https://championships-peoples-point-cassette.trycloudflare.com/prop.py" ascii wide nocase
        $n10 = "https://dl.k8s.io/release/$(curl" ascii wide nocase
        $n11 = "https://dl.k8s.io/release/stable.txt)/bin/linux/${ARCH}/kubectl&quot" ascii wide nocase
        $n12 = "https://investigation-launches-hearings-copying.trycloudflare.com/" ascii wide nocase
        $n13 = "https://souls-entire-defined-routes.trycloudflare.com/" ascii wide nocase
        $n14 = "https://souls-entire-defined-routes.trycloudflare.com/kamikaze.sh" ascii wide nocase
        $n15 = "https://souls-entire-defined-routes.trycloudflare.com/kube.py&quot" ascii wide nocase
        $n16 = "https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran" ascii wide nocase
        $n17 = "trycloudflare.com/" ascii wide nocase
        $n18 = "trycloudflare.com/kube.py&quot" ascii wide nocase
        $n19 = "trycloudflare.com/prop.py" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_teampcp_deploys_canisterworm_wiper_to_target_iranian_systems
{
    meta:
        description = "Indicators from Bulwark Black report: TeamPCP Deploys CanisterWorm Wiper to Target Iranian Systems"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/teampcp-deploys-canisterworm-wiper-to-target-iranian-systems/"
        date = "2026-03-24"
        net_indicators = 7
        file_hashes = 92
    strings:
        $n0 = "45.148.10.212" ascii wide
        $n1 = "plug-tab-protective-relay.trycloudflare.com" ascii wide nocase
        $n2 = "scan.aquasecurtiy.org" ascii wide nocase
        $n3 = "tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io" ascii wide nocase
        $n4 = "aquasecurtiy.org" ascii wide nocase
        $n5 = "https://scan.aquasecurtiy.org" ascii wide nocase
        $n6 = "https://tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io/" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha1(0, filesize) == "0891663bc55073747be0eb864fbec3727840945d" or
        hash.sha1(0, filesize) == "0d49ceb356f7d4735c63bd0d5c7e67665ec7f80c" or
        hash.sha1(0, filesize) == "18f01febc4c3cd70ce6b94b70e69ab866fc033f5" or
        hash.sha1(0, filesize) == "19851bef764b57ff95b35e66589f31949eeb229d" or
        hash.sha1(0, filesize) == "1d74e4cf63b7cf083cf92bf5923cf037f7011c6b" or
        hash.sha1(0, filesize) == "2297a1b967ecc05ba2285eb6af56ab4da554ecae" or
        hash.sha1(0, filesize) == "22e864e71155122e2834eb0c10d0e7e0b8f65aa3" or
        hash.sha1(0, filesize) == "252554b0e1130467f4301ba65c55a9c373508e35" or
        hash.sha1(0, filesize) == "276ca9680f6df9016db12f7c48571e5c4639451d" or
        hash.sha1(0, filesize) == "2a51c5c5bb1fd1f0e134c9754f1702cfa359c3dd" or
        hash.sha1(0, filesize) == "2b1dac84ff12ba56158b3a97e2941a587cb20da9" or
        hash.sha1(0, filesize) == "2e7964d59cd24d1fd2aa4d6a5f93b7f09ea96947" or
        hash.sha1(0, filesize) == "3201ddddd69a1419c6f1511a14c5945ba3217126" or
        hash.sha1(0, filesize) == "384add36b52014a0f99c0ab3a3d58bd47e53d00f" or
        hash.sha1(0, filesize) == "38623bf26706d51c45647909dcfb669825442804" or
        hash.sha1(0, filesize) == "386c0f18ac3d7f2ed33e2d884761119f4024ff8a" or
        hash.sha1(0, filesize) == "3c615ac0f29e743eda8863377f9776619fd2db76" or
        hash.sha1(0, filesize) == "3d1b5be1589a83fc98b82781c263708b2eb3b47b" or
        hash.sha1(0, filesize) == "3dffed04dc90cf1c548f40577d642c52241ec76c" or
        hash.sha1(0, filesize) == "405e91f329294fb696f55793203abf1f6aba9b40" or
        hash.sha1(0, filesize) == "4209dcadeaea6a7df69262fef1beeda940881d4d" or
        hash.sha1(0, filesize) == "4bdcc5d9ef3ddb42ccc9126e6c07faa3df2807e3" or
        hash.sha1(0, filesize) == "506d7ff06abc509692c600b5b69b4dc6ceaa4b15" or
        hash.sha1(0, filesize) == "555e7ad4c895c558c7214496df1cd56d1390c516" or
        hash.sha1(0, filesize) == "61fbe20b7589e6b61eedcd5fe1e958e1a95fbd13" or
        hash.sha1(0, filesize) == "66c90331c8b991e7895d37796ac712b5895dda3b" or
        hash.sha1(0, filesize) == "6d8d730153d6151e03549f276faca0275ed9c7b2" or
        hash.sha1(0, filesize) == "6ec7aaf336b7d2593d980908be9bc4fed6d407c6" or
        hash.sha1(0, filesize) == "6fc874a1f9d65052d4c67a314da1dae914f1daff" or
        hash.sha1(0, filesize) == "7550f14b64c1c724035a075b36e71423719a1f30" or
        hash.sha1(0, filesize) == "794b6d99daefd5e27ecb33e12691c4026739bf98" or
        hash.sha1(0, filesize) == "7a4b6f31edb8db48cc22a1d41e298b38c4a6417e" or
        hash.sha1(0, filesize) == "7b955a5ece1e1b085c12dac7ac10e0eb1f5b0d4d" or
        hash.sha1(0, filesize) == "7f6f0ce52a59bdfc5757c3982aac2353b58f4c73" or
        hash.sha1(0, filesize) == "820428afeb64484d311211658383ce7f79d31a0a" or
        hash.sha1(0, filesize) == "848d665ed24dc1a41f6b4b7c7ffac7693d6b37be" or
        hash.sha1(0, filesize) == "8519037888b189f13047371758f7aed2283c6b58" or
        hash.sha1(0, filesize) == "85cb72f1e8ee5e6e44488cd6cbdbca94722f96ed" or
        hash.sha1(0, filesize) == "8aa8af3ea1de8e968a3e49a40afb063692ab8eae" or
        hash.sha1(0, filesize) == "8ae5a08aec3013ee8f6132b2a9012b45002f8eaa" or
        hash.sha1(0, filesize) == "8afa9b9f9183b4e00c46e2b82d34047e3c177bd0" or
        hash.sha1(0, filesize) == "8cfb9c31cc944da57458555aa398bb99336d5a1f" or
        hash.sha1(0, filesize) == "9092287c0339a8102f91c5a257a7e27625d9d029" or
        hash.sha1(0, filesize) == "91d5e0a13afab54533a95f8019dd7530bd38a071" or
        hash.sha1(0, filesize) == "91e7c2c36dcad14149d8e455b960af62a2ffb275" or
        hash.sha1(0, filesize) == "9738180dd24427b8824445dbbc23c30ffc1cb0d8" or
        hash.sha1(0, filesize) == "985447b035c447c1ed45f38fad7ca7a4254cb668" or
        hash.sha1(0, filesize) == "99b93c070aac11b52dfc3e41a55cbb24a331ae75" or
        hash.sha1(0, filesize) == "9ba3c3cd3b23d033cd91253a9e61a4bf59c8a670" or
        hash.sha1(0, filesize) == "9c000ba9d482773cbbc2c3544d61b109bc9eb832" or
        hash.sha1(0, filesize) == "9e8968cb83234f0de0217aa8c934a68a317ee518" or
        hash.sha1(0, filesize) == "a5b4818debf2adbaba872aaffd6a0f64a26449fa" or
        hash.sha1(0, filesize) == "a9bc513ea7989e3234b395cafb8ed5ccc3755636" or
        hash.sha1(0, filesize) == "aa3c46a9643b18125abb8aefc13219014e9c4be8" or
        hash.sha1(0, filesize) == "ab6606b76e5a054be08cab3d07da323e90e751e8" or
        hash.sha1(0, filesize) == "ad623e14ebdfe82b9627811d57b9a39e283d6128" or
        hash.sha1(0, filesize) == "b7252377a3d82c73d497bfafa3eabe84de1d02c4" or
        hash.sha1(0, filesize) == "b745a35bad072d93a9b83080e9920ec52c6b5a27" or
        hash.sha1(0, filesize) == "b7befdc106c600585d3eec87d7e98e1c136839ae" or
        hash.sha1(0, filesize) == "b9faa60f85f6f780a34b8d0faaf45b3e3966fdda" or
        hash.sha1(0, filesize) == "bb75a9059c2d5803db49e6ed6c6f7e0b367f96be" or
        hash.sha1(0, filesize) == "c19401b2f58dc6d2632cb473d44be98dd8292a93" or
        hash.sha1(0, filesize) == "c5967f85626795f647d4bf6eb67227f9b79e02f5" or
        hash.sha1(0, filesize) == "cf1692a1fc7a47120e6508309765db7e33477946" or
        hash.sha1(0, filesize) == "cf19d27c8a7fb7a8bbf1e1000e9318749bcd82cf" or
        hash.sha1(0, filesize) == "d488f4388ff4aa268906e25c2144f1433a4edec2" or
        hash.sha1(0, filesize) == "da73ae0790e458e878b300b57ceb5f81ac573b46" or
        hash.sha1(0, filesize) == "ddb6697447a97198bdef9bae00215059eb5e8bc2" or
        hash.sha1(0, filesize) == "ddb94181dcbc723d96ffc07fddd14d97e4849016" or
        hash.sha1(0, filesize) == "ddb9da4475c1cef7d5389062bdfdfbdbd1394648" or
        hash.sha1(0, filesize) == "e0198fd2b6e1679e36d32933941182d9afa82f6f" or
        hash.sha1(0, filesize) == "e53b0483d08da44da9dfe8a84bf2837e5163699b" or
        hash.sha1(0, filesize) == "ea56cd31d82b853932d50f1144e95b21817e52cf" or
        hash.sha1(0, filesize) == "ef3a510e3f94df3ea9fcd01621155ca5f2c3bf5b" or
        hash.sha1(0, filesize) == "f4436225d8a5fd1715d3c2290d8a50643e726031" or
        hash.sha1(0, filesize) == "f4f1785be270ae13f36f6a8cfbf6faaae50e660a" or
        hash.sha1(0, filesize) == "f5c9fd927027beaa3760d2a84daa8b00e6e5ee21" or
        hash.sha1(0, filesize) == "f77738448eec70113cf711656914b61905b3bd47" or
        hash.sha1(0, filesize) == "fa4209b6182a4c1609ce34d40b67f5cfd7f00f53" or
        hash.sha1(0, filesize) == "fa78e67c0df002c509bcdea88677fb5e2fe6a9b1" or
        hash.sha1(0, filesize) == "fd090040b5f584f4fcbe466878cb204d0735dcf4" or
        hash.sha1(0, filesize) == "fd429cf86db999572f3d9ca7c54561fdf7d388a4" or
        hash.sha256(0, filesize) == "0880819ef821cff918960a39c1c1aada55a5593c61c608ea9215da858a86e349" or
        hash.sha256(0, filesize) == "6328a34b26a63423b555a61f89a6a0525a534e9c88584c815d937910f1ddd538" or
        hash.sha256(0, filesize) == "822dd269ec10459572dfaaefe163dae693c344249a0161953f0d5cdd110bd2a0" or
        hash.sha256(0, filesize) == "887e1f5b5b50162a60bd03b66269e0ae545d0aef0583c1c5b00972152ad7e073" or
        hash.sha256(0, filesize) == "bef7e2c5a92c4fa4af17791efc1e46311c0f304796f1172fce192f5efc40f5d7" or
        hash.sha256(0, filesize) == "d5edd791021b966fb6af0ace09319ace7b97d6642363ef27b3d5056ca654a94c" or
        hash.sha256(0, filesize) == "e6310d8a003d7ac101a6b1cd39ff6c6a88ee454b767c1bdce143e04bc1113243" or
        hash.sha256(0, filesize) == "e64e152afe2c722d750f10259626f357cdea40420c5eedae37969fbf13abbecf" or
        hash.sha256(0, filesize) == "ecce7ae5ffc9f57bb70efd3ea136a2923f701334a8cd47d4fbf01a97fd22859c" or
        hash.sha256(0, filesize) == "f7084b0229dce605ccc5506b14acd4d954a496da4b6134a294844ca8d601970d"
}

rule BulwarkBlack_hackers_exploit_cve_2025_32975_cvss_10_0_to_hijack_unpatched_quest_kace_sma_systems
{
    meta:
        description = "Indicators from Bulwark Black report: Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/hackers-exploit-cve-2025-32975-cvss-10-0-to-hijack-unpatched-quest-kace-sma-systems/"
        date = "2026-03-24"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "216.126.225.156" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_fbi_flash_alert_iranian_handala_hackers_weaponize_telegram_for_malware_c2_operations
{
    meta:
        description = "Indicators from Bulwark Black report: FBI Flash Alert: Iranian Handala Hackers Weaponize Telegram for Malware C2 Operations"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/fbi-flash-alert-iranian-handala-hackers-weaponize-telegram-for-malware-c2-operations/"
        date = "2026-03-23"
        net_indicators = 4
        file_hashes = 0
    strings:
        $n0 = "handala-hack.to" ascii wide nocase
        $n1 = "handala-redwanted.to" ascii wide nocase
        $n2 = "justicehomeland.org" ascii wide nocase
        $n3 = "karmabelow80.org" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_unit_42_warns_ai_agents_could_enable_gift_card_theft_and_returns_fraud_at_scale
{
    meta:
        description = "Indicators from Bulwark Black report: Unit 42 Warns: AI Agents Could Enable Gift Card Theft and Returns Fraud at Scale"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/unit-42-warns-ai-agents-could-enable-gift-card-theft-and-returns-fraud-at-scale/"
        date = "2026-03-23"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "xyz.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_cve_2026_33017_critical_langflow_ai_framework_vulnerability_exploited_within_20_hours_of_disclos
{
    meta:
        description = "Indicators from Bulwark Black report: CVE-2026-33017: Critical Langflow AI Framework Vulnerability Exploited Within 20 Hours of Disclosure"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/cve-2026-33017-critical-langflow-ai-framework-vulnerability-exploited-within-20-hours-of-disclosure/"
        date = "2026-03-22"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "173.212.205.251" ascii wide
        $n1 = "1.9.0.dev" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_darksword_ios_exploit_kit_russian_hackers_weaponize_six_vulnerabilities_for_full_iphone_takeover
{
    meta:
        description = "Indicators from Bulwark Black report: DarkSword iOS Exploit Kit: Russian Hackers Weaponize Six Vulnerabilities for Full iPhone Takeover"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/darksword-ios-exploit-kit-russian-hackers-weaponize-six-vulnerabilities-for-full-iphone-takeover/"
        date = "2026-03-21"
        net_indicators = 12
        file_hashes = 1
    strings:
        $n0 = "62.72.21.10" ascii wide
        $n1 = "72.60.98.48" ascii wide
        $n2 = "e5.malaymoil.com" ascii wide nocase
        $n3 = "sahibndn.io" ascii wide nocase
        $n4 = "sqwas.shapelie.com" ascii wide nocase
        $n5 = "static.cdncounter.net" ascii wide nocase
        $n6 = "systemgroup.com" ascii wide nocase
        $n7 = "cdncounter.net" ascii wide nocase
        $n8 = "https://static.cdncounter.net/assets/index.html" ascii wide nocase
        $n9 = "https://static.cdncounter.net/widgets.js?uhfiu27fajf2948fjfefaa42&quot;&gt;&lt;/script&gt" ascii wide nocase
        $n10 = "malaymoil.com" ascii wide nocase
        $n11 = "shapelie.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "2e5a56beb63f21d9347310412ae6efb29fd3db2d3a3fc0798865a29a3c578d35"
}

rule BulwarkBlack_cve_2026_33017_critical_langflow_ai_platform_flaw_exploited_within_20_hours_of_disclosure
{
    meta:
        description = "Indicators from Bulwark Black report: CVE-2026-33017: Critical Langflow AI Platform Flaw Exploited Within 20 Hours of Disclosure"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/cve-2026-33017-critical-langflow-ai-platform-flaw-exploited-within-20-hours-of-disclosure/"
        date = "2026-03-21"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "173.212.205.251" ascii wide
        $n1 = "1.9.0.dev" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_critical_langflow_ai_platform_flaw_cve_2026_33017_exploited_within_20_hours_of_disclosure
{
    meta:
        description = "Indicators from Bulwark Black report: Critical Langflow AI Platform Flaw CVE-2026-33017 Exploited Within 20 Hours of Disclosure"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/critical-langflow-ai-platform-flaw-cve-2026-33017-exploited-within-20-hours-of-disclosure/"
        date = "2026-03-21"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "173.212.205.251" ascii wide
        $n1 = "1.9.0.dev" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_glassworm_supply_chain_campaign_hijacks_72_open_vsx_extensions_to_target_developers
{
    meta:
        description = "Indicators from Bulwark Black report: GlassWorm Supply Chain Campaign Hijacks 72 Open VSX Extensions to Target Developers"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/glassworm-supply-chain-campaign-hijacks-72-open-vsx-extensions-to-target-developers/"
        date = "2026-03-17"
        net_indicators = 10
        file_hashes = 0
    strings:
        $n0 = "45.32.150.251" ascii wide
        $n1 = "45.32.151.157" ascii wide
        $n2 = "70.34.242.255" ascii wide
        $n3 = "angular-studio.ng" ascii wide nocase
        $n4 = "brategmaqendaalar-studio.pro" ascii wide nocase
        $n5 = "daeumer-web.es" ascii wide nocase
        $n6 = "oigotm.my" ascii wide nocase
        $n7 = "pessa07tm.my" ascii wide nocase
        $n8 = "publisher.name" ascii wide nocase
        $n9 = "studio-velte-distributor.pro" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_the_promptware_kill_chain_a_new_framework_for_understanding_ai_malware_attacks
{
    meta:
        description = "Indicators from Bulwark Black report: The Promptware Kill Chain: A New Framework for Understanding AI Malware Attacks"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/the-promptware-kill-chain-a-new-framework-for-understanding-ai-malware-attacks/"
        date = "2026-03-16"
        net_indicators = 7
        file_hashes = 0
    strings:
        $n0 = "Kore.ai" ascii wide nocase
        $n1 = "VerifiedVoting.org" ascii wide nocase
        $n2 = "doi.org" ascii wide nocase
        $n3 = "go.nature.com" ascii wide nocase
        $n4 = "www.schneier.com" ascii wide nocase
        $n5 = "https://doi.org/10.48550/arXiv.2509.14233" ascii wide nocase
        $n6 = "https://www.schneier.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_operation_lightning_global_takedown_of_socksescort_botnet_that_enslaved_369000_routers_in_163_co
{
    meta:
        description = "Indicators from Bulwark Black report: Operation Lightning: Global Takedown of SocksEscort Botnet That Enslaved 369,000 Routers in 163 Countries"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/operation-lightning-global-takedown-of-socksescort-botnet-that-enslaved-369000-routers-in-163-countries/"
        date = "2026-03-15"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "socksescort.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_pro_iranian_hackers_expand_targeting_of_us_critical_infrastructure_as_cyber_chaos_escalates
{
    meta:
        description = "Indicators from Bulwark Black report: Pro-Iranian Hackers Expand Targeting of US Critical Infrastructure as Cyber Chaos Escalates"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/pro-iranian-hackers-expand-targeting-of-us-critical-infrastructure-as-cyber-chaos-escalates/"
        date = "2026-03-14"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "ap.org" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_storm_2561_weaponizes_seo_poisoning_to_deploy_trojanized_vpn_clients_and_steal_enterprise_creden
{
    meta:
        description = "Indicators from Bulwark Black report: Storm-2561 Weaponizes SEO Poisoning to Deploy Trojanized VPN Clients and Steal Enterprise Credentials"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/storm-2561-weaponizes-seo-poisoning-to-deploy-trojanized-vpn-clients-and-steal-enterprise-credentials/"
        date = "2026-03-13"
        net_indicators = 22
        file_hashes = 11
    strings:
        $n0 = "194.76.226.93" ascii wide
        $n1 = "checkpoint-vpn.com" ascii wide nocase
        $n2 = "cisco-secure-client.es" ascii wide nocase
        $n3 = "forticlient-for-mac.com" ascii wide nocase
        $n4 = "forticlient-vpn.de" ascii wide nocase
        $n5 = "forticlient-vpn.fr" ascii wide nocase
        $n6 = "forticlient-vpn.it" ascii wide nocase
        $n7 = "forticlient.ca" ascii wide nocase
        $n8 = "forticlient.co" ascii wide nocase
        $n9 = "forticlient.co.uk" ascii wide nocase
        $n10 = "forticlient.no" ascii wide nocase
        $n11 = "fortinet-vpn.com" ascii wide nocase
        $n12 = "ivanti-pulsesecure.com" ascii wide nocase
        $n13 = "ivanti-secure-access.de" ascii wide nocase
        $n14 = "ivanti-vpn.org" ascii wide nocase
        $n15 = "myconnection.pro" ascii wide nocase
        $n16 = "pn-connection.pro" ascii wide nocase
        $n17 = "sonicwall-netextender.nl" ascii wide nocase
        $n18 = "sophos-connect.org" ascii wide nocase
        $n19 = "vpn-fortinet.com" ascii wide nocase
        $n20 = "watchguard-vpn.com" ascii wide nocase
        $n21 = "co.uk" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "26db3fd959f12a61d19d102c1a0fb5ee7ae3661fa2b301135cdb686298989179" or
        hash.sha256(0, filesize) == "44906752f500b61d436411a121cab8d88edf614e1140a2d01474bd587a8d7ba8" or
        hash.sha256(0, filesize) == "57a50a1c04254df3db638e75a64d5dd3b0d6a460829192277e252dc0c157a62f" or
        hash.sha256(0, filesize) == "6129d717e4e3a6fb4681463e421a5603b640bc6173fb7ba45a41a881c79415ca" or
        hash.sha256(0, filesize) == "6c9ab17a4aff2cdf408815ec120718f19f1a31c13fc5889167065d448a40dfe6" or
        hash.sha256(0, filesize) == "85c4837e3337165d24c6690ca63a3274dfaaa03b2ddaca7f1d18b3b169c6aac1" or
        hash.sha256(0, filesize) == "862f004679d3b142d9d2c729e78df716aeeda0c7a87a11324742a5a8eda9b557" or
        hash.sha256(0, filesize) == "8ebe082a4b52ad737f7ed33ccc61024c9f020fd085c7985e9c90dc2008a15adc" or
        hash.sha256(0, filesize) == "98f21b8fa426fc79aa82e28669faac9a9c7fce9b49d75bbec7b60167e21963c9" or
        hash.sha256(0, filesize) == "cfa4781ebfa5a8d68b233efb723dbde434ca70b2f76ff28127ecf13753bfe011" or
        hash.sha256(0, filesize) == "eb8b81277c80eeb3c094d0a168533b07366e759a8671af8bfbe12d8bc87650c9"
}

rule BulwarkBlack_infostealer_infection_unmasks_dprk_operative_behind_polyfill_io_supply_chain_attack_and_us_crypt
{
    meta:
        description = "Indicators from Bulwark Black report: Infostealer Infection Unmasks DPRK Operative Behind Polyfill.io Supply Chain Attack and US Crypto Exchange Infiltration"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/infostealer-infection-unmasks-dprk-operative-behind-polyfill-io-supply-chain-attack-and-us-crypto-exchange-infiltration/"
        date = "2026-03-12"
        net_indicators = 31
        file_hashes = 0
    strings:
        $n0 = "192.161.60.132" ascii wide
        $n1 = "Gate.io" ascii wide nocase
        $n2 = "Gate.us" ascii wide nocase
        $n3 = "Polyfill.io" ascii wide nocase
        $n4 = "apps.nulab.com" ascii wide nocase
        $n5 = "cctest.kk5yuzmev2qbgulz.com" ascii wide nocase
        $n6 = "cockpit.sumsub.com" ascii wide nocase
        $n7 = "discord.com" ascii wide nocase
        $n8 = "feee.io" ascii wide nocase
        $n9 = "friday.stark-industries.solutions" ascii wide nocase
        $n10 = "gy4q3fpx3gh77gw.kk5yuzmev2qbgulz.com" ascii wide nocase
        $n11 = "kk5yuzmev2qbgulz.com" ascii wide nocase
        $n12 = "lrtechs.backlog.com" ascii wide nocase
        $n13 = "lrtechs.co" ascii wide nocase
        $n14 = "lrtechs.co.jp" ascii wide nocase
        $n15 = "polyfill.com" ascii wide nocase
        $n16 = "polyfillcache.com" ascii wide nocase
        $n17 = "stark-industries.solutions" ascii wide nocase
        $n18 = "t2.funnull.host" ascii wide nocase
        $n19 = "vision.stark-industries.solutions" ascii wide nocase
        $n20 = "www.hudsonrock.com" ascii wide nocase
        $n21 = "www.mediafire.com" ascii wide nocase
        $n22 = "funnull.host" ascii wide nocase
        $n23 = "https://apps.nulab.com/signup/verify" ascii wide nocase
        $n24 = "https://cockpit.sumsub.com/checkus#/applicant/66a453df5137ba3da8742f58/basicInfo?clientId=gate.us_60664" ascii wide nocase
        $n25 = "https://discord.com/register" ascii wide nocase
        $n26 = "https://gy4q3fpx3gh77gw.kk5yuzmev2qbgulz.com/#/domin/list" ascii wide nocase
        $n27 = "https://lrtechs.backlog.com/dashboard" ascii wide nocase
        $n28 = "https://vision.stark-industries.solutions/auth/login" ascii wide nocase
        $n29 = "https://www.hudsonrock.com/schedule-demo" ascii wide nocase
        $n30 = "https://www.mediafire.com/file/gflsp6ovigjnvms/@#Full_Istaller_Pc_Setup_2024_PaSSW%E1%B9%8FrD^$.zip/file" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_kadnap_botnet_hijacks_14000_asus_routers_using_novel_kademlia_dht_protocol_for_stealth_c2
{
    meta:
        description = "Indicators from Bulwark Black report: KadNap Botnet Hijacks 14,000+ ASUS Routers Using Novel Kademlia DHT Protocol for Stealth C2"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/kadnap-botnet-hijacks-14000-asus-routers-using-novel-kademlia-dht-protocol-for-stealth-c2/"
        date = "2026-03-12"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "212.104.141.140" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_fortigate_devices_exploited_as_network_entry_points_for_service_account_credential_theft
{
    meta:
        description = "Indicators from Bulwark Black report: FortiGate Devices Exploited as Network Entry Points for Service Account Credential Theft"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/fortigate-devices-exploited-as-network-entry-points-for-service-account-credential-theft/"
        date = "2026-03-11"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "172.67.196.232" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_iranian_mois_cyber_actors_embrace_criminal_ecosystem_from_rhadamanthys_to_ransomware_affiliates
{
    meta:
        description = "Indicators from Bulwark Black report: Iranian MOIS Cyber Actors Embrace Criminal Ecosystem: From Rhadamanthys to Ransomware Affiliates"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/iranian-mois-cyber-actors-embrace-criminal-ecosystem-from-rhadamanthys-to-ransomware-affiliates/"
        date = "2026-03-11"
        net_indicators = 1
        file_hashes = 25
    strings:
        $n0 = "18.223.24.218" ascii wide
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "eb5e96e05129e5691f9677be4e396c88" or
        hash.sha1(0, filesize) == "0902d7915a19975817ec1ccb0f2f6714aed19638" or
        hash.sha1(0, filesize) == "2087bb914327e937ea6e77fe6c832576338c2af8" or
        hash.sha1(0, filesize) == "21a435ecaa7b86efbec7f6fb61fcda3da686125c" or
        hash.sha1(0, filesize) == "389b12da259a23fa4559eb1d97198120f2a722fe" or
        hash.sha1(0, filesize) == "551bdf646df8e9abe04483882650a8ffae43cb55" or
        hash.sha1(0, filesize) == "579a4584a6eef0a2453841453221d0fb25c08c89" or
        hash.sha1(0, filesize) == "9dcb994ea2b8e6169b76a524fae7b2d2dcd1807d" or
        hash.sha1(0, filesize) == "b674578d4bdb24cd58bf2dc884eaa658b7aa250c" or
        hash.sha1(0, filesize) == "d920ae0f8ea8b5bd42de49e01c6bbd4c2c6d0847" or
        hash.sha1(0, filesize) == "f8444dfc740b94227ab9b2e757b8f8f1fa49362a" or
        hash.sha256(0, filesize) == "077ab28d66abdafad9f5411e18d26e87fe43da1410ee8fe846bd721ab0cb52de" or
        hash.sha256(0, filesize) == "24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14" or
        hash.sha256(0, filesize) == "2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5" or
        hash.sha256(0, filesize) == "2b7d8a519f44d3105e9fde2770c75efb933994c658855dca7d48c8b4897f81e6" or
        hash.sha256(0, filesize) == "4aef998e3b3f6ca21c78ed71732c9d2bdcc8a4e0284f51d7462c79d446fbc7be" or
        hash.sha256(0, filesize) == "64263640a6fdeb2388bca2e9094a17065308cf8dcb0032454c0a71d9b78327eb" or
        hash.sha256(0, filesize) == "64cf334716f15da1db7981fad6c81a640d94aa1d65391ef879f4b7b6edf6e7f1" or
        hash.sha256(0, filesize) == "74db1f653da6de134bdc526412a517a30b6856de9c3e5d0c742cb5fe9959ad0d" or
        hash.sha256(0, filesize) == "94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444" or
        hash.sha256(0, filesize) == "a4bd1371fe644d7e6898045cc8e7b5e1562bdfd0e4871d46034e29a22dec6377" or
        hash.sha256(0, filesize) == "a8c380b57cb7c381ca6ba845bd7af7333f52ee4dc4e935e98b48bb81facad72b" or
        hash.sha256(0, filesize) == "a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0" or
        hash.sha256(0, filesize) == "aae017e7a36e016655c91bd01b4f3c46309bbe540733f82cce29392e72e9bd1f" or
        hash.sha256(0, filesize) == "ddceade244c636435f2444cd4c4d3dc161981f3af1f622c03442747ecef50888"
}

rule BulwarkBlack_blacksanta_edr_killer_campaign_targets_hr_departments_through_weaponized_resume_files
{
    meta:
        description = "Indicators from Bulwark Black report: BlackSanta EDR Killer Campaign Targets HR Departments Through Weaponized Resume Files"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/blacksanta-edr-killer-campaign-targets-hr-departments-through-weaponized-resume-files/"
        date = "2026-03-10"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "resumebuilders.us" ascii wide nocase
        $n1 = "thresumebuilder.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_boryptgrab_stealer_spreads_through_100_fake_github_repositories_in_massive_malware_campaign
{
    meta:
        description = "Indicators from Bulwark Black report: BoryptGrab Stealer Spreads Through 100+ Fake GitHub Repositories in Massive Malware Campaign"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/boryptgrab-stealer-spreads-through-100-fake-github-repositories-in-massive-malware-campaign/"
        date = "2026-03-09"
        net_indicators = 18
        file_hashes = 16
    strings:
        $n0 = "193.143.1.104" ascii wide
        $n1 = "45.93.20.195" ascii wide
        $n2 = "45.93.20.61" ascii wide
        $n3 = "best-tinted.com" ascii wide nocase
        $n4 = "botshield.vu" ascii wide nocase
        $n5 = "claude.ai" ascii wide nocase
        $n6 = "kiamatka.com" ascii wide nocase
        $n7 = "best-tinted.com/github-download.html" ascii wide nocase
        $n8 = "botshield.vu/KKRkm9" ascii wide nocase
        $n9 = "botshield.vu/kFcjld" ascii wide nocase
        $n10 = "http://193.143.1.104:5000" ascii wide nocase
        $n11 = "http://45.93.20.195:5000" ascii wide nocase
        $n12 = "http://45.93.20.61:5466/api/x32_chromium" ascii wide nocase
        $n13 = "https://best-tinted.com/github-download.html" ascii wide nocase
        $n14 = "https://botshield.vu/KKRkm9" ascii wide nocase
        $n15 = "https://botshield.vu/kFcjld" ascii wide nocase
        $n16 = "https://kiamatka.com/kaiok.kakman" ascii wide nocase
        $n17 = "kiamatka.com/kaiok.kakman" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "0434437a073a3f3a49e84d5ecb20c99dd551bacc32bf100fbb8cf67a50642181" or
        hash.sha256(0, filesize) == "15de71073f44c657c23f5f97caa11f1b12e654d4d17684bfc628cc1e5b6bcdd5" or
        hash.sha256(0, filesize) == "1bd605ef84b6767df74bd6290f1468eed5a88264df23fcf70b6a75d5bdcf7d76" or
        hash.sha256(0, filesize) == "2050468744e44554fac17fb83f1515c95f2f2236716e2b5267a81c2b94205e6a" or
        hash.sha256(0, filesize) == "2abe0ef88ba92db79d82cde4c0ed1f382bb347517a54ea82084c841d0f955518" or
        hash.sha256(0, filesize) == "4264a88035aa0b63e9aef96daa78a58114d60a344ea10168a8ef5ef36bf8edbd" or
        hash.sha256(0, filesize) == "433a13cc70396f80dc29d1150c050339d78964fdc91bcdc3f40c67a77add1476" or
        hash.sha256(0, filesize) == "449f528f5ceae8c3f8336d0d8e3e3ec9031d1ad67c31ee7311b67e01d5fdf225" or
        hash.sha256(0, filesize) == "4e90d386c1c7d3d1fd4176975795a2f432d95685690778e09313b4a1dbab9997" or
        hash.sha256(0, filesize) == "576692df4bf1c7d8927d3a183f5219a81c3bff3dd22971691f8af6889f80c5a0" or
        hash.sha256(0, filesize) == "7f2315b89fb9a47e1516def136844d617bfcdce19000a1b0436706692dbe166c" or
        hash.sha256(0, filesize) == "c40b9913e79c5dd09751b1afb03aaa98658bab61bacf27a299abd84fd44fe707" or
        hash.sha256(0, filesize) == "d295720bc0c1111ce1c3d8b1bc1b36ba840f103b3ca7e95a5a8bf03e2cc44fe5" or
        hash.sha256(0, filesize) == "ed1745cc49b929e499966d87e163219fe0f24069fe88dfacbd69c0ebab85a640" or
        hash.sha256(0, filesize) == "fa767391b99865f8533efc1fe6dfa6175215718679fb00ca85fc13c3bd4ae4b7" or
        hash.sha256(0, filesize) == "fe4e5fb28d2c2b3a640112b6b125ce8c4afa8be28342e3bfda097ad9dd2ef9ee"
}

rule BulwarkBlack_google_disrupts_chinese_apt_unc2814s_gridtide_backdoor_campaign_targeting_42_countries
{
    meta:
        description = "Indicators from Bulwark Black report: Google Disrupts Chinese APT UNC2814’s GRIDTIDE Backdoor Campaign Targeting 42 Countries"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/google-disrupts-chinese-apt-unc2814s-gridtide-backdoor-campaign-targeting-42-countries/"
        date = "2026-03-06"
        net_indicators = 237
        file_hashes = 6
    strings:
        $n0 = "130.94.6.228" ascii wide
        $n1 = "139.180.219.115" ascii wide
        $n2 = "139.84.236.237" ascii wide
        $n3 = "149.28.128.128" ascii wide
        $n4 = "149.28.139.125" ascii wide
        $n5 = "178.79.188.181" ascii wide
        $n6 = "195.123.211.70" ascii wide
        $n7 = "195.123.226.235" ascii wide
        $n8 = "202.59.10.122" ascii wide
        $n9 = "207.148.73.18" ascii wide
        $n10 = "38.180.205.14" ascii wide
        $n11 = "38.54.112.184" ascii wide
        $n12 = "38.54.31.146" ascii wide
        $n13 = "38.54.32.244" ascii wide
        $n14 = "38.54.37.196" ascii wide
        $n15 = "38.54.82.69" ascii wide
        $n16 = "38.60.171.242" ascii wide
        $n17 = "38.60.194.21" ascii wide
        $n18 = "38.60.224.25" ascii wide
        $n19 = "38.60.252.66" ascii wide
        $n20 = "45.76.157.113" ascii wide
        $n21 = "45.76.184.214" ascii wide
        $n22 = "45.77.254.168" ascii wide
        $n23 = "45.90.59.129" ascii wide
        $n24 = "5.34.176.6" ascii wide
        $n25 = "65.20.104.91" ascii wide
        $n26 = "1cv2f3d5s6a9w.ddnsfree.com" ascii wide nocase
        $n27 = "Boemobww.ddnsfree.com" ascii wide nocase
        $n28 = "DCLCWPDTSDCC.ddnsfree.com" ascii wide nocase
        $n29 = "Kaushalya.freeddns.org" ascii wide nocase
        $n30 = "Microsoft.bumbleshrimp.com" ascii wide nocase
        $n31 = "Mosplosaq.accesscam.org" ascii wide nocase
        $n32 = "Npeoples.theworkpc.com" ascii wide nocase
        $n33 = "PRIFTP.kozow.com" ascii wide nocase
        $n34 = "PolicyAgent.theworkpc.com" ascii wide nocase
        $n35 = "Scopps.ddnsgeek.com" ascii wide nocase
        $n36 = "Smartfren.giize.com" ascii wide nocase
        $n37 = "USOShared1.ddnsfree.com" ascii wide nocase
        $n38 = "accesscam.org" ascii wide nocase
        $n39 = "admina.freeddns.org" ascii wide nocase
        $n40 = "afsaces.accesscam.org" ascii wide nocase
        $n41 = "ancisesic.accesscam.org" ascii wide nocase
        $n42 = "applebox.camdvr.org" ascii wide nocase
        $n43 = "appler.kozow.com" ascii wide nocase
        $n44 = "asdad21ww.freeddns.org" ascii wide nocase
        $n45 = "aw2o25forsbc.camdvr.org" ascii wide nocase
        $n46 = "awcc001jdaigfwdagdcew.giize.com" ascii wide nocase
        $n47 = "bab2o25com.accesscam.org" ascii wide nocase
        $n48 = "babaji.accesscam.org" ascii wide nocase
        $n49 = "babi5599ss.ddnsgeek.com" ascii wide nocase
        $n50 = "balabalabo.mywire.org" ascii wide nocase
        $n51 = "bggs.giize.com" ascii wide nocase
        $n52 = "bibabo.freeddns.org" ascii wide nocase
        $n53 = "binmol.webredirect.org" ascii wide nocase
        $n54 = "bioth.giize.com" ascii wide nocase
        $n55 = "brcallletme.theworkpc.com" ascii wide nocase
        $n56 = "btbtutil.theworkpc.com" ascii wide nocase
        $n57 = "btltan.ooguy.com" ascii wide nocase
        $n58 = "bumbleshrimp.com" ascii wide nocase
        $n59 = "camcampkes.ddnsfree.com" ascii wide nocase
        $n60 = "camdvr.org" ascii wide nocase
        $n61 = "camsqewivo.kozow.com" ascii wide nocase
        $n62 = "casacam.net" ascii wide nocase
        $n63 = "ccammutom.ddnsgeek.com" ascii wide nocase
        $n64 = "cdnvmtools.theworkpc.com" ascii wide nocase
        $n65 = "cloacpae.ddnsfree.com" ascii wide nocase
        $n66 = "cmwwoods1.theworkpc.com" ascii wide nocase
        $n67 = "cnrpaslceas.freeddns.org" ascii wide nocase
        $n68 = "codemicros12.gleeze.com" ascii wide nocase
        $n69 = "cressmiss.ooguy.com" ascii wide nocase
        $n70 = "cvabiasbae.ddnsfree.com" ascii wide nocase
        $n71 = "cvnoc01da1cjmnftsd.accesscam.org" ascii wide nocase
        $n72 = "cvpc01aenusocirem.accesscam.org" ascii wide nocase
        $n73 = "cvpc01cgsdfn53hgd.giize.com" ascii wide nocase
        $n74 = "ddnsfree.com" ascii wide nocase
        $n75 = "ddnsgeek.com" ascii wide nocase
        $n76 = "dlpossie.ddnsfree.com" ascii wide nocase
        $n77 = "dnsfreedb.ddnsfree.com" ascii wide nocase
        $n78 = "doboudix1024.mywire.org" ascii wide nocase
        $n79 = "dynuddns.net" ascii wide nocase
        $n80 = "evilginx2.loseyourip.com" ascii wide nocase
        $n81 = "examp1e.webredirect.org" ascii wide nocase
        $n82 = "faeelt.giize.com" ascii wide nocase
        $n83 = "fakjcsaeyhs.ddnsfree.com" ascii wide nocase
        $n84 = "fasceadvcva3.gleeze.com" ascii wide nocase
        $n85 = "ffosies2024.camdvr.org" ascii wide nocase
        $n86 = "fgdedd1dww.gleeze.com" ascii wide nocase
        $n87 = "filipinet.ddnsgeek.com" ascii wide nocase
        $n88 = "freeddns.org" ascii wide nocase
        $n89 = "freeios.theworkpc.com" ascii wide nocase
        $n90 = "ftpuser14.gleeze.com" ascii wide nocase
        $n91 = "ftpzpak.kozow.com" ascii wide nocase
        $n92 = "giize.com" ascii wide nocase
        $n93 = "gleeze.com" ascii wide nocase
        $n94 = "globoss.kozow.com" ascii wide nocase
        $n95 = "gogo2025up.ddnsfree.com" ascii wide nocase
        $n96 = "googlel.gleeze.com" ascii wide nocase
        $n97 = "googles.accesscam.org" ascii wide nocase
        $n98 = "googles.ddnsfree.com" ascii wide nocase
        $n99 = "googlett.camdvr.org" ascii wide nocase
        $n100 = "googllabwws.gleeze.com" ascii wide nocase
        $n101 = "gtaldps31c.ddnsfree.com" ascii wide nocase
        $n102 = "hamkorg.kozow.com" ascii wide nocase
        $n103 = "honidoo.loseyourip.com" ascii wide nocase
        $n104 = "huygdr12.loseyourip.com" ascii wide nocase
        $n105 = "icekancusjhea.ddnsgeek.com" ascii wide nocase
        $n106 = "idstandsuui.kozow.com" ascii wide nocase
        $n107 = "indoodchat.theworkpc.com" ascii wide nocase
        $n108 = "jarvis001.freeddns.org" ascii wide nocase
        $n109 = "khyes001ndfpnuewdm.kozow.com" ascii wide nocase
        $n110 = "kozow.com" ascii wide nocase
        $n111 = "kskxoscieontrolanel.gleeze.com" ascii wide nocase
        $n112 = "ksv01sokudwongsj.theworkpc.com" ascii wide nocase
        $n113 = "lcskiecjj.loseyourip.com" ascii wide nocase
        $n114 = "lcskiecs.ddnsfree.com" ascii wide nocase
        $n115 = "loseyourip.com" ascii wide nocase
        $n116 = "losiesca.ddnsgeek.com" ascii wide nocase
        $n117 = "lps2staging.ddnsfree.com" ascii wide nocase
        $n118 = "lsls.casacam.net" ascii wide nocase
        $n119 = "ltiuys.ddnsgeek.com" ascii wide nocase
        $n120 = "ltiuys.kozow.com" ascii wide nocase
        $n121 = "mailsdy.gleeze.com" ascii wide nocase
        $n122 = "maliclick1.ddnsfree.com" ascii wide nocase
        $n123 = "mauritasszddb.ddnsfree.com" ascii wide nocase
        $n124 = "meetls.kozow.com" ascii wide nocase
        $n125 = "ml3.freeddns.org" ascii wide nocase
        $n126 = "mlksucnayesk.kozow.com" ascii wide nocase
        $n127 = "mmmfaco2025.mywire.org" ascii wide nocase
        $n128 = "mms.bumbleshrimp.com" ascii wide nocase
        $n129 = "mmvmtools.giize.com" ascii wide nocase
        $n130 = "modgood.gleeze.com" ascii wide nocase
        $n131 = "mysql.casacam.net" ascii wide nocase
        $n132 = "mywire.org" ascii wide nocase
        $n133 = "nenigncagvawr.giize.com" ascii wide nocase
        $n134 = "nenignenigoncqvoo.ooguy.com" ascii wide nocase
        $n135 = "nenigoncqnutgo.accesscam.org" ascii wide nocase
        $n136 = "nenigoncuopzc.giize.com" ascii wide nocase
        $n137 = "nims.gleeze.com" ascii wide nocase
        $n138 = "nisaldwoa.theworkpc.com" ascii wide nocase
        $n139 = "nmszablogs.ddnsfree.com" ascii wide nocase
        $n140 = "nodekeny11.freeddns.org" ascii wide nocase
        $n141 = "nodjs2o25nodjs.giize.com" ascii wide nocase
        $n142 = "officeshan.kozow.com" ascii wide nocase
        $n143 = "okkstt.ddnsgeek.com" ascii wide nocase
        $n144 = "oldatain1.ddnsgeek.com" ascii wide nocase
        $n145 = "onlyosun.ooguy.com" ascii wide nocase
        $n146 = "ooguy.com" ascii wide nocase
        $n147 = "osix.ddnsgeek.com" ascii wide nocase
        $n148 = "ovmmiuy.mywire.org" ascii wide nocase
        $n149 = "palamolscueajfvc.gleeze.com" ascii wide nocase
        $n150 = "pawanp.kozow.com" ascii wide nocase
        $n151 = "pcmainecia.ddnsfree.com" ascii wide nocase
        $n152 = "pcvmts3.kozow.com" ascii wide nocase
        $n153 = "peisuesacae.loseyourip.com" ascii wide nocase
        $n154 = "peowork.ddnsgeek.com" ascii wide nocase
        $n155 = "pepesetup.ddnsfree.com" ascii wide nocase
        $n156 = "pewsus.freeddns.org" ascii wide nocase
        $n157 = "plcoaweniva.ddnsgeek.com" ascii wide nocase
        $n158 = "polokinyea.gleeze.com" ascii wide nocase
        $n159 = "pplodsssead222.loseyourip.com" ascii wide nocase
        $n160 = "pplosad231.kozow.com" ascii wide nocase
        $n161 = "ppsaBedon.gleeze.com" ascii wide nocase
        $n162 = "prdanjana01.ddnsfree.com" ascii wide nocase
        $n163 = "prepaid127.freeddns.org" ascii wide nocase
        $n164 = "prihxlcs.ddnsfree.com" ascii wide nocase
        $n165 = "prihxlcsw.theworkpc.com" ascii wide nocase
        $n166 = "pxlaxvvva.freeddns.org" ascii wide nocase
        $n167 = "quitgod2023luck.giize.com" ascii wide nocase
        $n168 = "rabbit.ooguy.com" ascii wide nocase
        $n169 = "rsm323.kozow.com" ascii wide nocase
        $n170 = "saf3asg.giize.com" ascii wide nocase
        $n171 = "sdhite43.ddnsfree.com" ascii wide nocase
        $n172 = "sdsuytoins63.kozow.com" ascii wide nocase
        $n173 = "selfad.gleeze.com" ascii wide nocase
        $n174 = "serious.kozow.com" ascii wide nocase
        $n175 = "setupcodpr2.freeddns.org" ascii wide nocase
        $n176 = "sgsn.accesscam.org" ascii wide nocase
        $n177 = "sn0son4t31bbsvopou.camdvr.org" ascii wide nocase
        $n178 = "sn0son4t31opc.freeddns.org" ascii wide nocase
        $n179 = "soovuy.gleeze.com" ascii wide nocase
        $n180 = "styuij.mywire.org" ascii wide nocase
        $n181 = "supceasfg1.loseyourip.com" ascii wide nocase
        $n182 = "systemsz.kozow.com" ascii wide nocase
        $n183 = "t31c0mjumpcuyerop.ooguy.com" ascii wide nocase
        $n184 = "t31c0mopamcuiomx.kozow.com" ascii wide nocase
        $n185 = "t31c0mopmiuewklg.webredirect.org" ascii wide nocase
        $n186 = "t31c0mopocuveop.accesscam.org" ascii wide nocase
        $n187 = "t3lc0mcanyqbfac.loseyourip.com" ascii wide nocase
        $n188 = "t3lc0mczmoihwc.camdvr.org" ascii wide nocase
        $n189 = "t3lc0mh4udncifw.casacam.net" ascii wide nocase
        $n190 = "t3lc0mhasvnctsk.giize.com" ascii wide nocase
        $n191 = "t3lm0rtlcagratu.kozow.com" ascii wide nocase
        $n192 = "tch.giize.com" ascii wide nocase
        $n193 = "telcomn.giize.com" ascii wide nocase
        $n194 = "telen.bumbleshrimp.com" ascii wide nocase
        $n195 = "telkom.ooguy.com" ascii wide nocase
        $n196 = "telkomservices.theworkpc.com" ascii wide nocase
        $n197 = "thbio.kozow.com" ascii wide nocase
        $n198 = "theworkpc.com" ascii wide nocase
        $n199 = "timpe.kozow.com" ascii wide nocase
        $n200 = "timpe.webredirect.org" ascii wide nocase
        $n201 = "tlse001hdfuwwgdgpnn.theworkpc.com" ascii wide nocase
        $n202 = "tltlsktelko.ddnsfree.com" ascii wide nocase
        $n203 = "transport.dynuddns.net" ascii wide nocase
        $n204 = "trvcl.bumbleshrimp.com" ascii wide nocase
        $n205 = "ttsiou12.loseyourip.com" ascii wide nocase
        $n206 = "ua2o25yth.ddnsgeek.com" ascii wide nocase
        $n207 = "udieyg.gleeze.com" ascii wide nocase
        $n208 = "unnjunnani.ddnsfree.com" ascii wide nocase
        $n209 = "updatamail.kozow.com" ascii wide nocase
        $n210 = "updatasuccess.ddnsgeek.com" ascii wide nocase
        $n211 = "updateservices.kozow.com" ascii wide nocase
        $n212 = "updatetools.giize.com" ascii wide nocase
        $n213 = "uscplxsecjs.ddnsgeek.com" ascii wide nocase
        $n214 = "vals.bumbleshrimp.com" ascii wide nocase
        $n215 = "vass2025.casacam.net" ascii wide nocase
        $n216 = "vass.ooguy.com" ascii wide nocase
        $n217 = "vmtools.camdvr.org" ascii wide nocase
        $n218 = "vmtools.loseyourip.com" ascii wide nocase
        $n219 = "vosies.ddnsfree.com" ascii wide nocase
        $n220 = "vpaspmine.freeddns.org" ascii wide nocase
        $n221 = "wdlcamaakc.ooguy.com" ascii wide nocase
        $n222 = "webredirect.org" ascii wide nocase
        $n223 = "winfoss1.kozow.com" ascii wide nocase
        $n224 = "ysiohbk.camdvr.org" ascii wide nocase
        $n225 = "zammffayhd.ddnsfree.com" ascii wide nocase
        $n226 = "zmcmvmbm.ddnsfree.com" ascii wide nocase
        $n227 = "zwmn350n3o1fsdf3gs.kozow.com" ascii wide nocase
        $n228 = "zwmn350n3o1ugety2xbe.camdvr.org" ascii wide nocase
        $n229 = "zwmn350n3o1vsdrggs.ddnsfree.com" ascii wide nocase
        $n230 = "zwt310n3o1unety2kab.webredirect.org" ascii wide nocase
        $n231 = "zwt310n3o2unety6a3k.kozow.com" ascii wide nocase
        $n232 = "zwt31n3t0nidoqmve.camdvr.org" ascii wide nocase
        $n233 = "zwt3ln3t1aimckalw.theworkpc.com" ascii wide nocase
        $n234 = "http://130.94.6.228/amp.tar.gz" ascii wide nocase
        $n235 = "http://130.94.6.228/apt.tar.gz" ascii wide nocase
        $n236 = "http://130.94.6.228/update.tar.gz" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "01fc3bd5a78cd59255a867ffb3dfdd6e0b7713ee90098ea96cc01c640c6495eb" or
        hash.sha256(0, filesize) == "4eb994b816a1a24cf97bfd7551d00fe14b810859170dbf15180d39e05cd7c0f9" or
        hash.sha256(0, filesize) == "669917bad46a57e5f2de037f8ec200a44fb579d723af3e2f1be1e8479a267966" or
        hash.sha256(0, filesize) == "ce36a5fc44cbd7de947130b67be9e732a7b4086fb1df98a5afd724087c973b47" or
        hash.sha256(0, filesize) == "d25024ccea8eac85a9522289cfb709f2ed4e20176dd37855bacc2cd75c995606" or
        hash.sha256(0, filesize) == "eb08c840f4c95e2fa5eff05e5f922f86c766f5368a63476f046b2b9dbffc2033"
}

rule BulwarkBlack_google_and_mandiant_disrupt_gridtide_chinese_apt_espionage_campaign_compromises_53_victims_in_42
{
    meta:
        description = "Indicators from Bulwark Black report: Google and Mandiant Disrupt GRIDTIDE: Chinese APT Espionage Campaign Compromises 53 Victims in 42 Countries"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/google-and-mandiant-disrupt-gridtide-chinese-apt-espionage-campaign-compromises-53-victims-in-42-countries/"
        date = "2026-03-06"
        net_indicators = 237
        file_hashes = 6
    strings:
        $n0 = "130.94.6.228" ascii wide
        $n1 = "139.180.219.115" ascii wide
        $n2 = "139.84.236.237" ascii wide
        $n3 = "149.28.128.128" ascii wide
        $n4 = "149.28.139.125" ascii wide
        $n5 = "178.79.188.181" ascii wide
        $n6 = "195.123.211.70" ascii wide
        $n7 = "195.123.226.235" ascii wide
        $n8 = "202.59.10.122" ascii wide
        $n9 = "207.148.73.18" ascii wide
        $n10 = "38.180.205.14" ascii wide
        $n11 = "38.54.112.184" ascii wide
        $n12 = "38.54.31.146" ascii wide
        $n13 = "38.54.32.244" ascii wide
        $n14 = "38.54.37.196" ascii wide
        $n15 = "38.54.82.69" ascii wide
        $n16 = "38.60.171.242" ascii wide
        $n17 = "38.60.194.21" ascii wide
        $n18 = "38.60.224.25" ascii wide
        $n19 = "38.60.252.66" ascii wide
        $n20 = "45.76.157.113" ascii wide
        $n21 = "45.76.184.214" ascii wide
        $n22 = "45.77.254.168" ascii wide
        $n23 = "45.90.59.129" ascii wide
        $n24 = "5.34.176.6" ascii wide
        $n25 = "65.20.104.91" ascii wide
        $n26 = "1cv2f3d5s6a9w.ddnsfree.com" ascii wide nocase
        $n27 = "Boemobww.ddnsfree.com" ascii wide nocase
        $n28 = "DCLCWPDTSDCC.ddnsfree.com" ascii wide nocase
        $n29 = "Kaushalya.freeddns.org" ascii wide nocase
        $n30 = "Microsoft.bumbleshrimp.com" ascii wide nocase
        $n31 = "Mosplosaq.accesscam.org" ascii wide nocase
        $n32 = "Npeoples.theworkpc.com" ascii wide nocase
        $n33 = "PRIFTP.kozow.com" ascii wide nocase
        $n34 = "PolicyAgent.theworkpc.com" ascii wide nocase
        $n35 = "Scopps.ddnsgeek.com" ascii wide nocase
        $n36 = "Smartfren.giize.com" ascii wide nocase
        $n37 = "USOShared1.ddnsfree.com" ascii wide nocase
        $n38 = "accesscam.org" ascii wide nocase
        $n39 = "admina.freeddns.org" ascii wide nocase
        $n40 = "afsaces.accesscam.org" ascii wide nocase
        $n41 = "ancisesic.accesscam.org" ascii wide nocase
        $n42 = "applebox.camdvr.org" ascii wide nocase
        $n43 = "appler.kozow.com" ascii wide nocase
        $n44 = "asdad21ww.freeddns.org" ascii wide nocase
        $n45 = "aw2o25forsbc.camdvr.org" ascii wide nocase
        $n46 = "awcc001jdaigfwdagdcew.giize.com" ascii wide nocase
        $n47 = "bab2o25com.accesscam.org" ascii wide nocase
        $n48 = "babaji.accesscam.org" ascii wide nocase
        $n49 = "babi5599ss.ddnsgeek.com" ascii wide nocase
        $n50 = "balabalabo.mywire.org" ascii wide nocase
        $n51 = "bggs.giize.com" ascii wide nocase
        $n52 = "bibabo.freeddns.org" ascii wide nocase
        $n53 = "binmol.webredirect.org" ascii wide nocase
        $n54 = "bioth.giize.com" ascii wide nocase
        $n55 = "brcallletme.theworkpc.com" ascii wide nocase
        $n56 = "btbtutil.theworkpc.com" ascii wide nocase
        $n57 = "btltan.ooguy.com" ascii wide nocase
        $n58 = "bumbleshrimp.com" ascii wide nocase
        $n59 = "camcampkes.ddnsfree.com" ascii wide nocase
        $n60 = "camdvr.org" ascii wide nocase
        $n61 = "camsqewivo.kozow.com" ascii wide nocase
        $n62 = "casacam.net" ascii wide nocase
        $n63 = "ccammutom.ddnsgeek.com" ascii wide nocase
        $n64 = "cdnvmtools.theworkpc.com" ascii wide nocase
        $n65 = "cloacpae.ddnsfree.com" ascii wide nocase
        $n66 = "cmwwoods1.theworkpc.com" ascii wide nocase
        $n67 = "cnrpaslceas.freeddns.org" ascii wide nocase
        $n68 = "codemicros12.gleeze.com" ascii wide nocase
        $n69 = "cressmiss.ooguy.com" ascii wide nocase
        $n70 = "cvabiasbae.ddnsfree.com" ascii wide nocase
        $n71 = "cvnoc01da1cjmnftsd.accesscam.org" ascii wide nocase
        $n72 = "cvpc01aenusocirem.accesscam.org" ascii wide nocase
        $n73 = "cvpc01cgsdfn53hgd.giize.com" ascii wide nocase
        $n74 = "ddnsfree.com" ascii wide nocase
        $n75 = "ddnsgeek.com" ascii wide nocase
        $n76 = "dlpossie.ddnsfree.com" ascii wide nocase
        $n77 = "dnsfreedb.ddnsfree.com" ascii wide nocase
        $n78 = "doboudix1024.mywire.org" ascii wide nocase
        $n79 = "dynuddns.net" ascii wide nocase
        $n80 = "evilginx2.loseyourip.com" ascii wide nocase
        $n81 = "examp1e.webredirect.org" ascii wide nocase
        $n82 = "faeelt.giize.com" ascii wide nocase
        $n83 = "fakjcsaeyhs.ddnsfree.com" ascii wide nocase
        $n84 = "fasceadvcva3.gleeze.com" ascii wide nocase
        $n85 = "ffosies2024.camdvr.org" ascii wide nocase
        $n86 = "fgdedd1dww.gleeze.com" ascii wide nocase
        $n87 = "filipinet.ddnsgeek.com" ascii wide nocase
        $n88 = "freeddns.org" ascii wide nocase
        $n89 = "freeios.theworkpc.com" ascii wide nocase
        $n90 = "ftpuser14.gleeze.com" ascii wide nocase
        $n91 = "ftpzpak.kozow.com" ascii wide nocase
        $n92 = "giize.com" ascii wide nocase
        $n93 = "gleeze.com" ascii wide nocase
        $n94 = "globoss.kozow.com" ascii wide nocase
        $n95 = "gogo2025up.ddnsfree.com" ascii wide nocase
        $n96 = "googlel.gleeze.com" ascii wide nocase
        $n97 = "googles.accesscam.org" ascii wide nocase
        $n98 = "googles.ddnsfree.com" ascii wide nocase
        $n99 = "googlett.camdvr.org" ascii wide nocase
        $n100 = "googllabwws.gleeze.com" ascii wide nocase
        $n101 = "gtaldps31c.ddnsfree.com" ascii wide nocase
        $n102 = "hamkorg.kozow.com" ascii wide nocase
        $n103 = "honidoo.loseyourip.com" ascii wide nocase
        $n104 = "huygdr12.loseyourip.com" ascii wide nocase
        $n105 = "icekancusjhea.ddnsgeek.com" ascii wide nocase
        $n106 = "idstandsuui.kozow.com" ascii wide nocase
        $n107 = "indoodchat.theworkpc.com" ascii wide nocase
        $n108 = "jarvis001.freeddns.org" ascii wide nocase
        $n109 = "khyes001ndfpnuewdm.kozow.com" ascii wide nocase
        $n110 = "kozow.com" ascii wide nocase
        $n111 = "kskxoscieontrolanel.gleeze.com" ascii wide nocase
        $n112 = "ksv01sokudwongsj.theworkpc.com" ascii wide nocase
        $n113 = "lcskiecjj.loseyourip.com" ascii wide nocase
        $n114 = "lcskiecs.ddnsfree.com" ascii wide nocase
        $n115 = "loseyourip.com" ascii wide nocase
        $n116 = "losiesca.ddnsgeek.com" ascii wide nocase
        $n117 = "lps2staging.ddnsfree.com" ascii wide nocase
        $n118 = "lsls.casacam.net" ascii wide nocase
        $n119 = "ltiuys.ddnsgeek.com" ascii wide nocase
        $n120 = "ltiuys.kozow.com" ascii wide nocase
        $n121 = "mailsdy.gleeze.com" ascii wide nocase
        $n122 = "maliclick1.ddnsfree.com" ascii wide nocase
        $n123 = "mauritasszddb.ddnsfree.com" ascii wide nocase
        $n124 = "meetls.kozow.com" ascii wide nocase
        $n125 = "ml3.freeddns.org" ascii wide nocase
        $n126 = "mlksucnayesk.kozow.com" ascii wide nocase
        $n127 = "mmmfaco2025.mywire.org" ascii wide nocase
        $n128 = "mms.bumbleshrimp.com" ascii wide nocase
        $n129 = "mmvmtools.giize.com" ascii wide nocase
        $n130 = "modgood.gleeze.com" ascii wide nocase
        $n131 = "mysql.casacam.net" ascii wide nocase
        $n132 = "mywire.org" ascii wide nocase
        $n133 = "nenigncagvawr.giize.com" ascii wide nocase
        $n134 = "nenignenigoncqvoo.ooguy.com" ascii wide nocase
        $n135 = "nenigoncqnutgo.accesscam.org" ascii wide nocase
        $n136 = "nenigoncuopzc.giize.com" ascii wide nocase
        $n137 = "nims.gleeze.com" ascii wide nocase
        $n138 = "nisaldwoa.theworkpc.com" ascii wide nocase
        $n139 = "nmszablogs.ddnsfree.com" ascii wide nocase
        $n140 = "nodekeny11.freeddns.org" ascii wide nocase
        $n141 = "nodjs2o25nodjs.giize.com" ascii wide nocase
        $n142 = "officeshan.kozow.com" ascii wide nocase
        $n143 = "okkstt.ddnsgeek.com" ascii wide nocase
        $n144 = "oldatain1.ddnsgeek.com" ascii wide nocase
        $n145 = "onlyosun.ooguy.com" ascii wide nocase
        $n146 = "ooguy.com" ascii wide nocase
        $n147 = "osix.ddnsgeek.com" ascii wide nocase
        $n148 = "ovmmiuy.mywire.org" ascii wide nocase
        $n149 = "palamolscueajfvc.gleeze.com" ascii wide nocase
        $n150 = "pawanp.kozow.com" ascii wide nocase
        $n151 = "pcmainecia.ddnsfree.com" ascii wide nocase
        $n152 = "pcvmts3.kozow.com" ascii wide nocase
        $n153 = "peisuesacae.loseyourip.com" ascii wide nocase
        $n154 = "peowork.ddnsgeek.com" ascii wide nocase
        $n155 = "pepesetup.ddnsfree.com" ascii wide nocase
        $n156 = "pewsus.freeddns.org" ascii wide nocase
        $n157 = "plcoaweniva.ddnsgeek.com" ascii wide nocase
        $n158 = "polokinyea.gleeze.com" ascii wide nocase
        $n159 = "pplodsssead222.loseyourip.com" ascii wide nocase
        $n160 = "pplosad231.kozow.com" ascii wide nocase
        $n161 = "ppsaBedon.gleeze.com" ascii wide nocase
        $n162 = "prdanjana01.ddnsfree.com" ascii wide nocase
        $n163 = "prepaid127.freeddns.org" ascii wide nocase
        $n164 = "prihxlcs.ddnsfree.com" ascii wide nocase
        $n165 = "prihxlcsw.theworkpc.com" ascii wide nocase
        $n166 = "pxlaxvvva.freeddns.org" ascii wide nocase
        $n167 = "quitgod2023luck.giize.com" ascii wide nocase
        $n168 = "rabbit.ooguy.com" ascii wide nocase
        $n169 = "rsm323.kozow.com" ascii wide nocase
        $n170 = "saf3asg.giize.com" ascii wide nocase
        $n171 = "sdhite43.ddnsfree.com" ascii wide nocase
        $n172 = "sdsuytoins63.kozow.com" ascii wide nocase
        $n173 = "selfad.gleeze.com" ascii wide nocase
        $n174 = "serious.kozow.com" ascii wide nocase
        $n175 = "setupcodpr2.freeddns.org" ascii wide nocase
        $n176 = "sgsn.accesscam.org" ascii wide nocase
        $n177 = "sn0son4t31bbsvopou.camdvr.org" ascii wide nocase
        $n178 = "sn0son4t31opc.freeddns.org" ascii wide nocase
        $n179 = "soovuy.gleeze.com" ascii wide nocase
        $n180 = "styuij.mywire.org" ascii wide nocase
        $n181 = "supceasfg1.loseyourip.com" ascii wide nocase
        $n182 = "systemsz.kozow.com" ascii wide nocase
        $n183 = "t31c0mjumpcuyerop.ooguy.com" ascii wide nocase
        $n184 = "t31c0mopamcuiomx.kozow.com" ascii wide nocase
        $n185 = "t31c0mopmiuewklg.webredirect.org" ascii wide nocase
        $n186 = "t31c0mopocuveop.accesscam.org" ascii wide nocase
        $n187 = "t3lc0mcanyqbfac.loseyourip.com" ascii wide nocase
        $n188 = "t3lc0mczmoihwc.camdvr.org" ascii wide nocase
        $n189 = "t3lc0mh4udncifw.casacam.net" ascii wide nocase
        $n190 = "t3lc0mhasvnctsk.giize.com" ascii wide nocase
        $n191 = "t3lm0rtlcagratu.kozow.com" ascii wide nocase
        $n192 = "tch.giize.com" ascii wide nocase
        $n193 = "telcomn.giize.com" ascii wide nocase
        $n194 = "telen.bumbleshrimp.com" ascii wide nocase
        $n195 = "telkom.ooguy.com" ascii wide nocase
        $n196 = "telkomservices.theworkpc.com" ascii wide nocase
        $n197 = "thbio.kozow.com" ascii wide nocase
        $n198 = "theworkpc.com" ascii wide nocase
        $n199 = "timpe.kozow.com" ascii wide nocase
        $n200 = "timpe.webredirect.org" ascii wide nocase
        $n201 = "tlse001hdfuwwgdgpnn.theworkpc.com" ascii wide nocase
        $n202 = "tltlsktelko.ddnsfree.com" ascii wide nocase
        $n203 = "transport.dynuddns.net" ascii wide nocase
        $n204 = "trvcl.bumbleshrimp.com" ascii wide nocase
        $n205 = "ttsiou12.loseyourip.com" ascii wide nocase
        $n206 = "ua2o25yth.ddnsgeek.com" ascii wide nocase
        $n207 = "udieyg.gleeze.com" ascii wide nocase
        $n208 = "unnjunnani.ddnsfree.com" ascii wide nocase
        $n209 = "updatamail.kozow.com" ascii wide nocase
        $n210 = "updatasuccess.ddnsgeek.com" ascii wide nocase
        $n211 = "updateservices.kozow.com" ascii wide nocase
        $n212 = "updatetools.giize.com" ascii wide nocase
        $n213 = "uscplxsecjs.ddnsgeek.com" ascii wide nocase
        $n214 = "vals.bumbleshrimp.com" ascii wide nocase
        $n215 = "vass2025.casacam.net" ascii wide nocase
        $n216 = "vass.ooguy.com" ascii wide nocase
        $n217 = "vmtools.camdvr.org" ascii wide nocase
        $n218 = "vmtools.loseyourip.com" ascii wide nocase
        $n219 = "vosies.ddnsfree.com" ascii wide nocase
        $n220 = "vpaspmine.freeddns.org" ascii wide nocase
        $n221 = "wdlcamaakc.ooguy.com" ascii wide nocase
        $n222 = "webredirect.org" ascii wide nocase
        $n223 = "winfoss1.kozow.com" ascii wide nocase
        $n224 = "ysiohbk.camdvr.org" ascii wide nocase
        $n225 = "zammffayhd.ddnsfree.com" ascii wide nocase
        $n226 = "zmcmvmbm.ddnsfree.com" ascii wide nocase
        $n227 = "zwmn350n3o1fsdf3gs.kozow.com" ascii wide nocase
        $n228 = "zwmn350n3o1ugety2xbe.camdvr.org" ascii wide nocase
        $n229 = "zwmn350n3o1vsdrggs.ddnsfree.com" ascii wide nocase
        $n230 = "zwt310n3o1unety2kab.webredirect.org" ascii wide nocase
        $n231 = "zwt310n3o2unety6a3k.kozow.com" ascii wide nocase
        $n232 = "zwt31n3t0nidoqmve.camdvr.org" ascii wide nocase
        $n233 = "zwt3ln3t1aimckalw.theworkpc.com" ascii wide nocase
        $n234 = "http://130.94.6.228/amp.tar.gz" ascii wide nocase
        $n235 = "http://130.94.6.228/apt.tar.gz" ascii wide nocase
        $n236 = "http://130.94.6.228/update.tar.gz" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "01fc3bd5a78cd59255a867ffb3dfdd6e0b7713ee90098ea96cc01c640c6495eb" or
        hash.sha256(0, filesize) == "4eb994b816a1a24cf97bfd7551d00fe14b810859170dbf15180d39e05cd7c0f9" or
        hash.sha256(0, filesize) == "669917bad46a57e5f2de037f8ec200a44fb579d723af3e2f1be1e8479a267966" or
        hash.sha256(0, filesize) == "ce36a5fc44cbd7de947130b67be9e732a7b4086fb1df98a5afd724087c973b47" or
        hash.sha256(0, filesize) == "d25024ccea8eac85a9522289cfb709f2ed4e20176dd37855bacc2cd75c995606" or
        hash.sha256(0, filesize) == "eb08c840f4c95e2fa5eff05e5f922f86c766f5368a63476f046b2b9dbffc2033"
}

rule BulwarkBlack_uat_9244_china_nexus_apt_deploys_three_new_malware_implants_against_south_american_telecom_provi
{
    meta:
        description = "Indicators from Bulwark Black report: UAT-9244: China-Nexus APT Deploys Three New Malware Implants Against South American Telecom Providers"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/uat-9244-china-nexus-apt-deploys-three-new-malware-implants-against-south-american-telecom-providers/"
        date = "2026-03-05"
        net_indicators = 27
        file_hashes = 45
    strings:
        $n0 = "149.28.25.33" ascii wide
        $n1 = "154.205.154.194" ascii wide
        $n2 = "154.205.154.65" ascii wide
        $n3 = "154.205.154.70" ascii wide
        $n4 = "154.205.154.82" ascii wide
        $n5 = "154.223.21.130" ascii wide
        $n6 = "154.223.21.194" ascii wide
        $n7 = "158.247.238.240" ascii wide
        $n8 = "185.196.10.247" ascii wide
        $n9 = "185.196.10.38" ascii wide
        $n10 = "207.148.120.52" ascii wide
        $n11 = "207.148.121.95" ascii wide
        $n12 = "212.11.64.105" ascii wide
        $n13 = "216.238.112.222" ascii wide
        $n14 = "216.238.123.242" ascii wide
        $n15 = "216.238.94.37" ascii wide
        $n16 = "38.54.125.134" ascii wide
        $n17 = "38.60.199.34" ascii wide
        $n18 = "45.32.106.94" ascii wide
        $n19 = "45.77.34.194" ascii wide
        $n20 = "45.77.41.141" ascii wide
        $n21 = "47.76.100.159" ascii wide
        $n22 = "64.190.113.170" ascii wide
        $n23 = "64.95.10.253" ascii wide
        $n24 = "bloopencil.net" ascii wide nocase
        $n25 = "xcit76.com" ascii wide nocase
        $n26 = "xtibh.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha1(0, filesize) == "2b170a6d90fceba72aba3c7bc5c40b9725f43788" or
        hash.sha256(0, filesize) == "00735a8a50d2856c11150ef1e29c05acebce7ad3edad00e37c7f043aacb46330" or
        hash.sha256(0, filesize) == "023467e236a95d5f0e62e26445d430d749c59312f66cf136e6e2c2d526c46ba1" or
        hash.sha256(0, filesize) == "03eac9eb7f4b4bc494ef0496ee23cabbf38f883896838ed813741d8f64ac9fde" or
        hash.sha256(0, filesize) == "06b23d84fd7afd525dfd7860ebd561dcdd72ccbeb51981d5d9a75acf068d0a2a" or
        hash.sha256(0, filesize) == "075b20a21ea6a0d2201a12a049f332ecc61348fc0ad3cfee038c6ad6aa44e744" or
        hash.sha256(0, filesize) == "0c7e36683a100a96f695a952cf07052af9a47f5898e1078311fd58c5fdbdecc8" or
        hash.sha256(0, filesize) == "15d937803f90c2b9e277ff94d3e98ff30015ecc7f4623a158e3c98861e5cb278" or
        hash.sha256(0, filesize) == "17652d7bb5fe0454023db4fc7f608df0dbe6af237be31258e16ba52f0e895e26" or
        hash.sha256(0, filesize) == "1cedf01dd4b7e50181d0e781825c66957b862941395d77c8bd7705114f319c80" or
        hash.sha256(0, filesize) == "1f5635a512a923e98a90cdc1b2fb988a2da78706e07e419dae9e1a54dd4d682b" or
        hash.sha256(0, filesize) == "1fcdd5a417db31e5e07d32cecfa69e53f0dce95b7130ad9c03b92249f001801d" or
        hash.sha256(0, filesize) == "2c3f2261b00ea45e25eb4e9de2b7ff8e41f311c0b3d986461f834022c08b3b99" or
        hash.sha256(0, filesize) == "2d2ca7d21310b14f5f5641bbf4a9ff4c3e566b1fbbd370034c6844cedc8f0538" or
        hash.sha256(0, filesize) == "34d64b3cd9430e85edefcb883973a086dd5de9917e05fabec89b1f4ab9627e91" or
        hash.sha256(0, filesize) == "38eeaa4eaad72feb3f8e6993565fcc548d8e7bb93642590f00fa24aacc0e2862" or
        hash.sha256(0, filesize) == "3c098a687947938e36ab34b9f09a11ebd82d50089cbfe6e237d810faa729f8ff" or
        hash.sha256(0, filesize) == "3d9fbfc2c056eac857ba54e5ed134aa45a4b8322ee9f9353ba32e5b2ca71b0e3" or
        hash.sha256(0, filesize) == "3fcadde4b414a18b2fed56c1ec59d97977123615fbbf411a1c78425445a6e71c" or
        hash.sha256(0, filesize) == "3fcced9332301ff70b20c98c9434c858400013d659afa6bb5149cffb0206357d" or
        hash.sha256(0, filesize) == "56bead2933e91366e4a0d5761daf5b238a7f2c22e597664ef67b3ecae20ab326" or
        hash.sha256(0, filesize) == "66adeedfb739774fcc09aa7426c8fad29f8047ab4caee8040d07c0e84d011611" or
        hash.sha256(0, filesize) == "66bdce93de3b02cf9cdadad18ca1504ac83e379a752d51f60deae6dcbafe4e31" or
        hash.sha256(0, filesize) == "66ce42258062e902bd7f9e90ad5453a901cfc424f0ea497c4d14f063f3acd329" or
        hash.sha256(0, filesize) == "6a2d23cc8746a83e9a3b974788fce0e414706b8e75ff390426dd7e10b19967b3" or
        hash.sha256(0, filesize) == "6ec070457d1f6f239cb02c5e1576a3660cca98f3a07eec6e4e107f698d7fe555" or
        hash.sha256(0, filesize) == "711d9427ee43bc2186b9124f31cba2db5f54ec9a0d56dc2948e1a4377bada289" or
        hash.sha256(0, filesize) == "74d1a678bdc4bb9f33321e94e3bd1bc1740472ed734231fc46af720072ecb77e" or
        hash.sha256(0, filesize) == "74fbc8360d4c95d64d7acaa4d18943dce2d41f91d080b0b5e435d8bce52861a5" or
        hash.sha256(0, filesize) == "7b70cd956f082b1029d02b4cb7608893f2de7fa9c500d7d7febdd0f745ac3cb6" or
        hash.sha256(0, filesize) == "870e791af14caaf395c56028176a9c3f4c1ff0318ef3112d57ecd3d4a1be2ef9" or
        hash.sha256(0, filesize) == "9a7225c17e4bad3ffe7f080530d36f4f8aca5c116b913caa91ab9b0cee85638e" or
        hash.sha256(0, filesize) == "a5e413456ce9fc60bb44d442b72546e9e4118a61894fbe4b5c56e4dfad6055e3" or
        hash.sha256(0, filesize) == "a313f76fca50fff1bcd6f2c6cbc1268985f8c0a3a05fe7f43c4fc0ac3aff84dc" or
        hash.sha256(0, filesize) == "babc81fc9c998e9dc4ab545f0e112e34d2641e1333bc81aaa131abd061a5b604" or
        hash.sha256(0, filesize) == "bfc35f12d00fa4b40c5fbce9e37d704e12a52262709bcbdf09f97890bc40cad5" or
        hash.sha256(0, filesize) == "c9a42423ef08bd7f183915780d39530eba5e4e25968c51965ff8bb3026965a28" or
        hash.sha256(0, filesize) == "c9fc2af30f769d856b88b3051f19fdb663b3e0a0916279df9bbcba93c6a110c9" or
        hash.sha256(0, filesize) == "d5eb979cb8a72706bfa591fa57d4ebf7d13cecdc9377b0192375e2f570f796df" or
        hash.sha256(0, filesize) == "d78b3c6df8f3756a7e310cf7435fdba201dd03ec9f97420a0db683489a01a7c9" or
        hash.sha256(0, filesize) == "e34c9159e6e78c59518a14c5b96bddfee094b684f99d4f69b13371284a014e87" or
        hash.sha256(0, filesize) == "ebcb2691b7c92cdf2b2ff5e2d753abeea8cb325c16596cd839e6bd147f80e38a" or
        hash.sha256(0, filesize) == "f36913607356a32ea106103387105c635fa923f8ed98ad0194b66ec79e379a02" or
        hash.sha256(0, filesize) == "f3e899789b56429f483e5096e1f473335024f1f763e2d428132338e30352b89e" or
        hash.sha256(0, filesize) == "f8066833e47814793d8c58743622b051070dac09cb010c323970c81b59260f84"
}

rule BulwarkBlack_open_source_cyberstrikeai_tool_weaponized_in_ai_driven_fortigate_attacks_across_55_countries
{
    meta:
        description = "Indicators from Bulwark Black report: Open-Source CyberStrikeAI Tool Weaponized in AI-Driven FortiGate Attacks Across 55 Countries"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/open-source-cyberstrikeai-tool-weaponized-in-ai-driven-fortigate-attacks-across-55-countries/"
        date = "2026-03-04"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "212.11.64.250" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_zerobot_malware_targets_n8n_automation_platform_first_active_exploitation_of_cve_2025_68613
{
    meta:
        description = "Indicators from Bulwark Black report: Zerobot Malware Targets n8n Automation Platform: First Active Exploitation of CVE-2025-68613"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/zerobot-malware-targets-n8n-automation-platform-first-active-exploitation-of-cve-2025-68613/"
        date = "2026-03-04"
        net_indicators = 10
        file_hashes = 6
    strings:
        $n0 = "103.59.160.237" ascii wide
        $n1 = "140.233.190.96" ascii wide
        $n2 = "144.172.100.228" ascii wide
        $n3 = "172.86.123.179" ascii wide
        $n4 = "216.126.227.101" ascii wide
        $n5 = "0bot.qzz.io" ascii wide nocase
        $n6 = "andro.notemacro.com" ascii wide nocase
        $n7 = "pivot.notemacro.com" ascii wide nocase
        $n8 = "notemacro.com" ascii wide nocase
        $n9 = "qzz.io" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "045a1e42cb64e4aa91601f65a80ec5bd040ea4024c6d3b051cb1a6aa15d03b57" or
        hash.sha256(0, filesize) == "360467c3b733513c922b90d0e222067509df6481636926fa1786d0273169f4da" or
        hash.sha256(0, filesize) == "c8e8b627398ece071a3a148d6f38e46763dc534f9bfd967ebc8ac3479540111f" or
        hash.sha256(0, filesize) == "cc1efbca0da739b7784d833e56a22063ec4719cd095b16e3e10f77efd4277e24" or
        hash.sha256(0, filesize) == "d024039824db6fe535ddd51bc81099c946871e4e280c48ed6e90dada79ccfcc7" or
        hash.sha256(0, filesize) == "deb70af83a9b3bb8f9424b709c3f6342d0c63aa10e7f8df43dd7a457bda8f060"
}

rule BulwarkBlack_silver_dragon_apt_targets_southeast_asia_and_europe_using_geardoor_backdoor_with_google_drive_c2
{
    meta:
        description = "Indicators from Bulwark Black report: Silver Dragon APT Targets Southeast Asia and Europe Using GearDoor Backdoor with Google Drive C2"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/silver-dragon-apt-targets-southeast-asia-and-europe-using-geardoor-backdoor-with-google-drive-c2/"
        date = "2026-03-03"
        net_indicators = 19
        file_hashes = 32
    strings:
        $n0 = "104.21.51.8" ascii wide
        $n1 = "ampolice.org" ascii wide nocase
        $n2 = "bigflx.net" ascii wide nocase
        $n3 = "copilot-cloud.net" ascii wide nocase
        $n4 = "drivefrontend.pa" ascii wide nocase
        $n5 = "drivefrontend.pa-clients.workers.dev" ascii wide nocase
        $n6 = "exchange4study.com" ascii wide nocase
        $n7 = "mindssurpass.com" ascii wide nocase
        $n8 = "ns1.exchange4study.com" ascii wide nocase
        $n9 = "ns1.onedriveconsole.com" ascii wide nocase
        $n10 = "ns2.onedriveconsole.com" ascii wide nocase
        $n11 = "oicm.org" ascii wide nocase
        $n12 = "onedriveconsole.com" ascii wide nocase
        $n13 = "protacik.com" ascii wide nocase
        $n14 = "revitpourtous.com" ascii wide nocase
        $n15 = "splunkds.com" ascii wide nocase
        $n16 = "wikipedla.blog" ascii wide nocase
        $n17 = "zhydromet.com" ascii wide nocase
        $n18 = "workers.dev" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "9d3f61dcaba90db2ede1c1906a80ace2" or
        hash.sha256(0, filesize) == "166e777cb72a7c4e126f8ed97e0a82e7ca9e87df7793fea811daf34e1e7e47a6" or
        hash.sha256(0, filesize) == "16b9a7358be88632378ba20ba1430786f3b844694b1f876211ecdbecf5cccbc2" or
        hash.sha256(0, filesize) == "19139a525ee9c22efd6a4842c4cd50ab2c5f9ee391e5531071df0bb4e685f55d" or
        hash.sha256(0, filesize) == "2f787c1454891b242ab221b8b8b420373c3eb1a0c1fdcb624dd800c50758bbb0" or
        hash.sha256(0, filesize) == "3128bdb8efaaa04c0ba96337252f4cc2dc795021cbc410f74ace9dde958bac1d" or
        hash.sha256(0, filesize) == "37b485ed8d150d022c41e5e307b8c54c34ef806625b44d0c940b18be7d5b29ce" or
        hash.sha256(0, filesize) == "3a2df7a2cfeca5ba315a29cf313268a53a22316c925e6b9760ead8f4df0d1f75" or
        hash.sha256(0, filesize) == "3e2a0bafbd44e24b17fd7b17c9f2b2a3727349971d42612d55bbc1732082619a" or
        hash.sha256(0, filesize) == "43f8f94ca5aa0af7bfb0cc1d2f664a46500a161b2d082b48b516d084ef485348" or
        hash.sha256(0, filesize) == "44e769efed3e4f9f04c52dcd13f15cead251a1a08827a2cb6ea68427522c7fbb" or
        hash.sha256(0, filesize) == "4f93be0c46a53701b1777ab8df874c837df3d8256e026f138d60fc2932e569a8" or
        hash.sha256(0, filesize) == "51684a0e356513486489986f5832c948107ff687c8501d64846cdc4307429413" or
        hash.sha256(0, filesize) == "5341c7256542405abdd01ee288b08e49dcb6d1782be6b7bea63b459d80f9a8f5" or
        hash.sha256(0, filesize) == "568c67564d62b09d1a1bc29a494cf4bf31afddcafcf78592b178c63f23ccfcae" or
        hash.sha256(0, filesize) == "5ad857df8976523cb3ad2fdf30e87c0e7daa64135716b139ffdcd209b98e1654" or
        hash.sha256(0, filesize) == "72e4b6540e32b8b7aac850055609bc5afc19e29834e9aa6be29a8ea59a2c9785" or
        hash.sha256(0, filesize) == "7384462d420bdc9683a4cac2a8ad19353a2aa7d2244c91e9182345777e811e33" or
        hash.sha256(0, filesize) == "740a09fcdefa5a5f79355b720f54ff09efa64062229fb388adbccd9c829e9ff0" or
        hash.sha256(0, filesize) == "74a11a07d167f8f5c0baa724d1f7708985c81d0ac3d0e4d7ef3f3220c335e009" or
        hash.sha256(0, filesize) == "7f89a4d5af47bc00a9ad58f0bcbe8a7be2662953dcd03f0e881cc5cbf6b7bca8" or
        hash.sha256(0, filesize) == "85a03d2e74ae84093a74699057693d11e5c61f85b62e741778cbc5fc9f89022f" or
        hash.sha256(0, filesize) == "8c29f9189a9ad75a959024f59e68c62d42a6fd42f9eacf847128c7efe4ef7578" or
        hash.sha256(0, filesize) == "948468aba5c851952ebe56a5bf37904ed83a6c8cb520304db6938d79892f0a1b" or
        hash.sha256(0, filesize) == "967b5c611d304385807ea2d865fa561c15cde0473dd63e768679a4f29f0e4563" or
        hash.sha256(0, filesize) == "a6b5448ba45f3f352f5f4c5376024891adda1ef8ebf62a8fe63424fa230c691d" or
        hash.sha256(0, filesize) == "b93560c4d18120e113fb8b04a8aa05f66a12116d1fbf18a93186f6314381e97e" or
        hash.sha256(0, filesize) == "bcbe2f0a8134c0e7fce18d0394ababc1d910e6f7b77b8c07643434cd14f4c5d6" or
        hash.sha256(0, filesize) == "bd699ed720e2bd7085b3444cb8f4d36870b5b48df1055ec6cc1553db3eef7faf" or
        hash.sha256(0, filesize) == "c4de1f1a8cb3b0392802ee56096ddb25b6f51c51350ce7c45e14d8c285765300" or
        hash.sha256(0, filesize) == "ddaca57f3d5f4986da052ca172631b351410d6f5831f6af351699c6201cc011b" or
        hash.sha256(0, filesize) == "e3b016f2fc865d0f53f635f740eb0203626517425ed9a2908058f96a3bcf470d"
}

rule BulwarkBlack_apt28_exploited_cve_2026_21513_mshtml_zero_day_as_attack_vector_before_february_patch_tuesday
{
    meta:
        description = "Indicators from Bulwark Black report: APT28 Exploited CVE-2026-21513 MSHTML Zero-Day as Attack Vector Before February Patch Tuesday"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/apt28-exploited-cve-2026-21513-mshtml-zero-day-as-attack-vector-before-february-patch-tuesday/"
        date = "2026-03-03"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "wellnesscaremed.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_malicious_go_crypto_module_steals_passwords_and_deploys_rekoobe_backdoor
{
    meta:
        description = "Indicators from Bulwark Black report: Malicious Go Crypto Module Steals Passwords and Deploys Rekoobe Backdoor"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/malicious-go-crypto-module-steals-passwords-and-deploys-rekoobe-backdoor/"
        date = "2026-03-03"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "154.84.63.184" ascii wide
        $n1 = "go.googlesource.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_fake_google_security_check_transforms_browser_into_surveillance_toolkit_via_pwa_installation
{
    meta:
        description = "Indicators from Bulwark Black report: Fake Google Security Check Transforms Browser Into Surveillance Toolkit via PWA Installation"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/fake-google-security-check-transforms-browser-into-surveillance-toolkit-via-pwa-installation/"
        date = "2026-03-02"
        net_indicators = 1
        file_hashes = 1
    strings:
        $n0 = "google-prism.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "1fe2be4582c4cbce8013c3506bc8b46f850c23937a564d17e5e170d6f60d8c08"
}

rule BulwarkBlack_google_disrupts_unc2814_gridtide_campaign_chinese_apt_breaches_53_organizations_across_42_countr
{
    meta:
        description = "Indicators from Bulwark Black report: Google Disrupts UNC2814 GRIDTIDE Campaign: Chinese APT Breaches 53 Organizations Across 42 Countries"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/google-disrupts-unc2814-gridtide-campaign-chinese-apt-breaches-53-organizations-across-42-countries/"
        date = "2026-03-01"
        net_indicators = 237
        file_hashes = 6
    strings:
        $n0 = "130.94.6.228" ascii wide
        $n1 = "139.180.219.115" ascii wide
        $n2 = "139.84.236.237" ascii wide
        $n3 = "149.28.128.128" ascii wide
        $n4 = "149.28.139.125" ascii wide
        $n5 = "178.79.188.181" ascii wide
        $n6 = "195.123.211.70" ascii wide
        $n7 = "195.123.226.235" ascii wide
        $n8 = "202.59.10.122" ascii wide
        $n9 = "207.148.73.18" ascii wide
        $n10 = "38.180.205.14" ascii wide
        $n11 = "38.54.112.184" ascii wide
        $n12 = "38.54.31.146" ascii wide
        $n13 = "38.54.32.244" ascii wide
        $n14 = "38.54.37.196" ascii wide
        $n15 = "38.54.82.69" ascii wide
        $n16 = "38.60.171.242" ascii wide
        $n17 = "38.60.194.21" ascii wide
        $n18 = "38.60.224.25" ascii wide
        $n19 = "38.60.252.66" ascii wide
        $n20 = "45.76.157.113" ascii wide
        $n21 = "45.76.184.214" ascii wide
        $n22 = "45.77.254.168" ascii wide
        $n23 = "45.90.59.129" ascii wide
        $n24 = "5.34.176.6" ascii wide
        $n25 = "65.20.104.91" ascii wide
        $n26 = "1cv2f3d5s6a9w.ddnsfree.com" ascii wide nocase
        $n27 = "Boemobww.ddnsfree.com" ascii wide nocase
        $n28 = "DCLCWPDTSDCC.ddnsfree.com" ascii wide nocase
        $n29 = "Kaushalya.freeddns.org" ascii wide nocase
        $n30 = "Microsoft.bumbleshrimp.com" ascii wide nocase
        $n31 = "Mosplosaq.accesscam.org" ascii wide nocase
        $n32 = "Npeoples.theworkpc.com" ascii wide nocase
        $n33 = "PRIFTP.kozow.com" ascii wide nocase
        $n34 = "PolicyAgent.theworkpc.com" ascii wide nocase
        $n35 = "Scopps.ddnsgeek.com" ascii wide nocase
        $n36 = "Smartfren.giize.com" ascii wide nocase
        $n37 = "USOShared1.ddnsfree.com" ascii wide nocase
        $n38 = "accesscam.org" ascii wide nocase
        $n39 = "admina.freeddns.org" ascii wide nocase
        $n40 = "afsaces.accesscam.org" ascii wide nocase
        $n41 = "ancisesic.accesscam.org" ascii wide nocase
        $n42 = "applebox.camdvr.org" ascii wide nocase
        $n43 = "appler.kozow.com" ascii wide nocase
        $n44 = "asdad21ww.freeddns.org" ascii wide nocase
        $n45 = "aw2o25forsbc.camdvr.org" ascii wide nocase
        $n46 = "awcc001jdaigfwdagdcew.giize.com" ascii wide nocase
        $n47 = "bab2o25com.accesscam.org" ascii wide nocase
        $n48 = "babaji.accesscam.org" ascii wide nocase
        $n49 = "babi5599ss.ddnsgeek.com" ascii wide nocase
        $n50 = "balabalabo.mywire.org" ascii wide nocase
        $n51 = "bggs.giize.com" ascii wide nocase
        $n52 = "bibabo.freeddns.org" ascii wide nocase
        $n53 = "binmol.webredirect.org" ascii wide nocase
        $n54 = "bioth.giize.com" ascii wide nocase
        $n55 = "brcallletme.theworkpc.com" ascii wide nocase
        $n56 = "btbtutil.theworkpc.com" ascii wide nocase
        $n57 = "btltan.ooguy.com" ascii wide nocase
        $n58 = "bumbleshrimp.com" ascii wide nocase
        $n59 = "camcampkes.ddnsfree.com" ascii wide nocase
        $n60 = "camdvr.org" ascii wide nocase
        $n61 = "camsqewivo.kozow.com" ascii wide nocase
        $n62 = "casacam.net" ascii wide nocase
        $n63 = "ccammutom.ddnsgeek.com" ascii wide nocase
        $n64 = "cdnvmtools.theworkpc.com" ascii wide nocase
        $n65 = "cloacpae.ddnsfree.com" ascii wide nocase
        $n66 = "cmwwoods1.theworkpc.com" ascii wide nocase
        $n67 = "cnrpaslceas.freeddns.org" ascii wide nocase
        $n68 = "codemicros12.gleeze.com" ascii wide nocase
        $n69 = "cressmiss.ooguy.com" ascii wide nocase
        $n70 = "cvabiasbae.ddnsfree.com" ascii wide nocase
        $n71 = "cvnoc01da1cjmnftsd.accesscam.org" ascii wide nocase
        $n72 = "cvpc01aenusocirem.accesscam.org" ascii wide nocase
        $n73 = "cvpc01cgsdfn53hgd.giize.com" ascii wide nocase
        $n74 = "ddnsfree.com" ascii wide nocase
        $n75 = "ddnsgeek.com" ascii wide nocase
        $n76 = "dlpossie.ddnsfree.com" ascii wide nocase
        $n77 = "dnsfreedb.ddnsfree.com" ascii wide nocase
        $n78 = "doboudix1024.mywire.org" ascii wide nocase
        $n79 = "dynuddns.net" ascii wide nocase
        $n80 = "evilginx2.loseyourip.com" ascii wide nocase
        $n81 = "examp1e.webredirect.org" ascii wide nocase
        $n82 = "faeelt.giize.com" ascii wide nocase
        $n83 = "fakjcsaeyhs.ddnsfree.com" ascii wide nocase
        $n84 = "fasceadvcva3.gleeze.com" ascii wide nocase
        $n85 = "ffosies2024.camdvr.org" ascii wide nocase
        $n86 = "fgdedd1dww.gleeze.com" ascii wide nocase
        $n87 = "filipinet.ddnsgeek.com" ascii wide nocase
        $n88 = "freeddns.org" ascii wide nocase
        $n89 = "freeios.theworkpc.com" ascii wide nocase
        $n90 = "ftpuser14.gleeze.com" ascii wide nocase
        $n91 = "ftpzpak.kozow.com" ascii wide nocase
        $n92 = "giize.com" ascii wide nocase
        $n93 = "gleeze.com" ascii wide nocase
        $n94 = "globoss.kozow.com" ascii wide nocase
        $n95 = "gogo2025up.ddnsfree.com" ascii wide nocase
        $n96 = "googlel.gleeze.com" ascii wide nocase
        $n97 = "googles.accesscam.org" ascii wide nocase
        $n98 = "googles.ddnsfree.com" ascii wide nocase
        $n99 = "googlett.camdvr.org" ascii wide nocase
        $n100 = "googllabwws.gleeze.com" ascii wide nocase
        $n101 = "gtaldps31c.ddnsfree.com" ascii wide nocase
        $n102 = "hamkorg.kozow.com" ascii wide nocase
        $n103 = "honidoo.loseyourip.com" ascii wide nocase
        $n104 = "huygdr12.loseyourip.com" ascii wide nocase
        $n105 = "icekancusjhea.ddnsgeek.com" ascii wide nocase
        $n106 = "idstandsuui.kozow.com" ascii wide nocase
        $n107 = "indoodchat.theworkpc.com" ascii wide nocase
        $n108 = "jarvis001.freeddns.org" ascii wide nocase
        $n109 = "khyes001ndfpnuewdm.kozow.com" ascii wide nocase
        $n110 = "kozow.com" ascii wide nocase
        $n111 = "kskxoscieontrolanel.gleeze.com" ascii wide nocase
        $n112 = "ksv01sokudwongsj.theworkpc.com" ascii wide nocase
        $n113 = "lcskiecjj.loseyourip.com" ascii wide nocase
        $n114 = "lcskiecs.ddnsfree.com" ascii wide nocase
        $n115 = "loseyourip.com" ascii wide nocase
        $n116 = "losiesca.ddnsgeek.com" ascii wide nocase
        $n117 = "lps2staging.ddnsfree.com" ascii wide nocase
        $n118 = "lsls.casacam.net" ascii wide nocase
        $n119 = "ltiuys.ddnsgeek.com" ascii wide nocase
        $n120 = "ltiuys.kozow.com" ascii wide nocase
        $n121 = "mailsdy.gleeze.com" ascii wide nocase
        $n122 = "maliclick1.ddnsfree.com" ascii wide nocase
        $n123 = "mauritasszddb.ddnsfree.com" ascii wide nocase
        $n124 = "meetls.kozow.com" ascii wide nocase
        $n125 = "ml3.freeddns.org" ascii wide nocase
        $n126 = "mlksucnayesk.kozow.com" ascii wide nocase
        $n127 = "mmmfaco2025.mywire.org" ascii wide nocase
        $n128 = "mms.bumbleshrimp.com" ascii wide nocase
        $n129 = "mmvmtools.giize.com" ascii wide nocase
        $n130 = "modgood.gleeze.com" ascii wide nocase
        $n131 = "mysql.casacam.net" ascii wide nocase
        $n132 = "mywire.org" ascii wide nocase
        $n133 = "nenigncagvawr.giize.com" ascii wide nocase
        $n134 = "nenignenigoncqvoo.ooguy.com" ascii wide nocase
        $n135 = "nenigoncqnutgo.accesscam.org" ascii wide nocase
        $n136 = "nenigoncuopzc.giize.com" ascii wide nocase
        $n137 = "nims.gleeze.com" ascii wide nocase
        $n138 = "nisaldwoa.theworkpc.com" ascii wide nocase
        $n139 = "nmszablogs.ddnsfree.com" ascii wide nocase
        $n140 = "nodekeny11.freeddns.org" ascii wide nocase
        $n141 = "nodjs2o25nodjs.giize.com" ascii wide nocase
        $n142 = "officeshan.kozow.com" ascii wide nocase
        $n143 = "okkstt.ddnsgeek.com" ascii wide nocase
        $n144 = "oldatain1.ddnsgeek.com" ascii wide nocase
        $n145 = "onlyosun.ooguy.com" ascii wide nocase
        $n146 = "ooguy.com" ascii wide nocase
        $n147 = "osix.ddnsgeek.com" ascii wide nocase
        $n148 = "ovmmiuy.mywire.org" ascii wide nocase
        $n149 = "palamolscueajfvc.gleeze.com" ascii wide nocase
        $n150 = "pawanp.kozow.com" ascii wide nocase
        $n151 = "pcmainecia.ddnsfree.com" ascii wide nocase
        $n152 = "pcvmts3.kozow.com" ascii wide nocase
        $n153 = "peisuesacae.loseyourip.com" ascii wide nocase
        $n154 = "peowork.ddnsgeek.com" ascii wide nocase
        $n155 = "pepesetup.ddnsfree.com" ascii wide nocase
        $n156 = "pewsus.freeddns.org" ascii wide nocase
        $n157 = "plcoaweniva.ddnsgeek.com" ascii wide nocase
        $n158 = "polokinyea.gleeze.com" ascii wide nocase
        $n159 = "pplodsssead222.loseyourip.com" ascii wide nocase
        $n160 = "pplosad231.kozow.com" ascii wide nocase
        $n161 = "ppsaBedon.gleeze.com" ascii wide nocase
        $n162 = "prdanjana01.ddnsfree.com" ascii wide nocase
        $n163 = "prepaid127.freeddns.org" ascii wide nocase
        $n164 = "prihxlcs.ddnsfree.com" ascii wide nocase
        $n165 = "prihxlcsw.theworkpc.com" ascii wide nocase
        $n166 = "pxlaxvvva.freeddns.org" ascii wide nocase
        $n167 = "quitgod2023luck.giize.com" ascii wide nocase
        $n168 = "rabbit.ooguy.com" ascii wide nocase
        $n169 = "rsm323.kozow.com" ascii wide nocase
        $n170 = "saf3asg.giize.com" ascii wide nocase
        $n171 = "sdhite43.ddnsfree.com" ascii wide nocase
        $n172 = "sdsuytoins63.kozow.com" ascii wide nocase
        $n173 = "selfad.gleeze.com" ascii wide nocase
        $n174 = "serious.kozow.com" ascii wide nocase
        $n175 = "setupcodpr2.freeddns.org" ascii wide nocase
        $n176 = "sgsn.accesscam.org" ascii wide nocase
        $n177 = "sn0son4t31bbsvopou.camdvr.org" ascii wide nocase
        $n178 = "sn0son4t31opc.freeddns.org" ascii wide nocase
        $n179 = "soovuy.gleeze.com" ascii wide nocase
        $n180 = "styuij.mywire.org" ascii wide nocase
        $n181 = "supceasfg1.loseyourip.com" ascii wide nocase
        $n182 = "systemsz.kozow.com" ascii wide nocase
        $n183 = "t31c0mjumpcuyerop.ooguy.com" ascii wide nocase
        $n184 = "t31c0mopamcuiomx.kozow.com" ascii wide nocase
        $n185 = "t31c0mopmiuewklg.webredirect.org" ascii wide nocase
        $n186 = "t31c0mopocuveop.accesscam.org" ascii wide nocase
        $n187 = "t3lc0mcanyqbfac.loseyourip.com" ascii wide nocase
        $n188 = "t3lc0mczmoihwc.camdvr.org" ascii wide nocase
        $n189 = "t3lc0mh4udncifw.casacam.net" ascii wide nocase
        $n190 = "t3lc0mhasvnctsk.giize.com" ascii wide nocase
        $n191 = "t3lm0rtlcagratu.kozow.com" ascii wide nocase
        $n192 = "tch.giize.com" ascii wide nocase
        $n193 = "telcomn.giize.com" ascii wide nocase
        $n194 = "telen.bumbleshrimp.com" ascii wide nocase
        $n195 = "telkom.ooguy.com" ascii wide nocase
        $n196 = "telkomservices.theworkpc.com" ascii wide nocase
        $n197 = "thbio.kozow.com" ascii wide nocase
        $n198 = "theworkpc.com" ascii wide nocase
        $n199 = "timpe.kozow.com" ascii wide nocase
        $n200 = "timpe.webredirect.org" ascii wide nocase
        $n201 = "tlse001hdfuwwgdgpnn.theworkpc.com" ascii wide nocase
        $n202 = "tltlsktelko.ddnsfree.com" ascii wide nocase
        $n203 = "transport.dynuddns.net" ascii wide nocase
        $n204 = "trvcl.bumbleshrimp.com" ascii wide nocase
        $n205 = "ttsiou12.loseyourip.com" ascii wide nocase
        $n206 = "ua2o25yth.ddnsgeek.com" ascii wide nocase
        $n207 = "udieyg.gleeze.com" ascii wide nocase
        $n208 = "unnjunnani.ddnsfree.com" ascii wide nocase
        $n209 = "updatamail.kozow.com" ascii wide nocase
        $n210 = "updatasuccess.ddnsgeek.com" ascii wide nocase
        $n211 = "updateservices.kozow.com" ascii wide nocase
        $n212 = "updatetools.giize.com" ascii wide nocase
        $n213 = "uscplxsecjs.ddnsgeek.com" ascii wide nocase
        $n214 = "vals.bumbleshrimp.com" ascii wide nocase
        $n215 = "vass2025.casacam.net" ascii wide nocase
        $n216 = "vass.ooguy.com" ascii wide nocase
        $n217 = "vmtools.camdvr.org" ascii wide nocase
        $n218 = "vmtools.loseyourip.com" ascii wide nocase
        $n219 = "vosies.ddnsfree.com" ascii wide nocase
        $n220 = "vpaspmine.freeddns.org" ascii wide nocase
        $n221 = "wdlcamaakc.ooguy.com" ascii wide nocase
        $n222 = "webredirect.org" ascii wide nocase
        $n223 = "winfoss1.kozow.com" ascii wide nocase
        $n224 = "ysiohbk.camdvr.org" ascii wide nocase
        $n225 = "zammffayhd.ddnsfree.com" ascii wide nocase
        $n226 = "zmcmvmbm.ddnsfree.com" ascii wide nocase
        $n227 = "zwmn350n3o1fsdf3gs.kozow.com" ascii wide nocase
        $n228 = "zwmn350n3o1ugety2xbe.camdvr.org" ascii wide nocase
        $n229 = "zwmn350n3o1vsdrggs.ddnsfree.com" ascii wide nocase
        $n230 = "zwt310n3o1unety2kab.webredirect.org" ascii wide nocase
        $n231 = "zwt310n3o2unety6a3k.kozow.com" ascii wide nocase
        $n232 = "zwt31n3t0nidoqmve.camdvr.org" ascii wide nocase
        $n233 = "zwt3ln3t1aimckalw.theworkpc.com" ascii wide nocase
        $n234 = "http://130.94.6.228/amp.tar.gz" ascii wide nocase
        $n235 = "http://130.94.6.228/apt.tar.gz" ascii wide nocase
        $n236 = "http://130.94.6.228/update.tar.gz" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "01fc3bd5a78cd59255a867ffb3dfdd6e0b7713ee90098ea96cc01c640c6495eb" or
        hash.sha256(0, filesize) == "4eb994b816a1a24cf97bfd7551d00fe14b810859170dbf15180d39e05cd7c0f9" or
        hash.sha256(0, filesize) == "669917bad46a57e5f2de037f8ec200a44fb579d723af3e2f1be1e8479a267966" or
        hash.sha256(0, filesize) == "ce36a5fc44cbd7de947130b67be9e732a7b4086fb1df98a5afd724087c973b47" or
        hash.sha256(0, filesize) == "d25024ccea8eac85a9522289cfb709f2ed4e20176dd37855bacc2cd75c995606" or
        hash.sha256(0, filesize) == "eb08c840f4c95e2fa5eff05e5f922f86c766f5368a63476f046b2b9dbffc2033"
}

rule BulwarkBlack_apt37_ruby_jumper_campaign_north_korean_hackers_deploy_malware_arsenal_to_bridge_air_gapped_netw
{
    meta:
        description = "Indicators from Bulwark Black report: APT37 Ruby Jumper Campaign: North Korean Hackers Deploy Malware Arsenal to Bridge Air-Gapped Networks"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/apt37-ruby-jumper-campaign-north-korean-hackers-deploy-malware-arsenal-to-bridge-air-gapped-networks/"
        date = "2026-02-27"
        net_indicators = 13
        file_hashes = 9
    strings:
        $n0 = "144.172.106.66" ascii wide
        $n1 = "hightkdhe.store" ascii wide nocase
        $n2 = "homeatedke.store" ascii wide nocase
        $n3 = "philion.store" ascii wide nocase
        $n4 = "www.hightkdhe.store" ascii wide nocase
        $n5 = "www.homeatedke.store" ascii wide nocase
        $n6 = "www.philion.store" ascii wide nocase
        $n7 = "hightkdhe.store/star/main.php" ascii wide nocase
        $n8 = "homeatedke.store/star/main.php" ascii wide nocase
        $n9 = "https://www.hightkdhe.store/star/main.php" ascii wide nocase
        $n10 = "https://www.homeatedke.store/star/main.php" ascii wide nocase
        $n11 = "https://www.philion.store/star/main.php" ascii wide nocase
        $n12 = "philion.store/star/main.php" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "098d697f29b94c11b52c51bfe8f9c47d" or
        hash.md5(0, filesize) == "4214818d7cde26ebeb4f35bc2fc29ada" or
        hash.md5(0, filesize) == "476bce9b9a387c5f39461d781e7e22b9" or
        hash.md5(0, filesize) == "57dac5f7d21da2454d0fbefdced80bf3" or
        hash.md5(0, filesize) == "585322a931a49f4e1d78fb0b3f3c6212" or
        hash.md5(0, filesize) == "5c6ff601ccc75e76c2fc99808d8cc9a9" or
        hash.md5(0, filesize) == "709d70239f1e9441e8e21fcacfdc5d08" or
        hash.md5(0, filesize) == "ad556f4eb48e7dba6da14444dcce3170" or
        hash.md5(0, filesize) == "ed54cf1ebffbfc1c8ae1ccdd2c681012"
}

rule BulwarkBlack_uac_0050_targets_european_financial_institution_in_strategic_phishing_campaign
{
    meta:
        description = "Indicators from Bulwark Black report: UAC-0050 Targets European Financial Institution in Strategic Phishing Campaign"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/uac-0050-targets-european-financial-institution-in-strategic-phishing-campaign/"
        date = "2026-02-27"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "ThemesDNA.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_chinese_apt_campaign_delivers_plugx_rat_via_g_data_antivirus_dll_side_loading
{
    meta:
        description = "Indicators from Bulwark Black report: Chinese APT Campaign Delivers PlugX RAT via G DATA Antivirus DLL Side-Loading"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/chinese-apt-campaign-delivers-plugx-rat-via-g-data-antivirus-dll-side-loading/"
        date = "2026-02-27"
        net_indicators = 10
        file_hashes = 8
    strings:
        $n0 = "decoorat.net" ascii wide nocase
        $n1 = "decoraat.net" ascii wide nocase
        $n2 = "gesecole.net" ascii wide nocase
        $n3 = "onedow.gesecole.net" ascii wide nocase
        $n4 = "onedown.gesecole.net" ascii wide nocase
        $n5 = "https://decoraat.net:443" ascii wide nocase
        $n6 = "https://onedow.gesecole.net/download" ascii wide nocase
        $n7 = "https://onedown.gesecole.net/download" ascii wide nocase
        $n8 = "onedow.gesecole.net/download" ascii wide nocase
        $n9 = "onedown.gesecole.net/download" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "29cd44aa2a51a200d82cca578d97dc13241bc906ea6a33b132c6ca567dc8f3ad" or
        hash.sha256(0, filesize) == "46314092c8d00ab93cbbdc824b9fc39dec9303169163b9625bae3b1717d70ebc" or
        hash.sha256(0, filesize) == "5f9af68db10b029453264cfc9b8eee4265549a2855bb79668ccfc571fb11f5fc" or
        hash.sha256(0, filesize) == "6df8649bf4e233ee86a896ee8e5a3b3179c168ef927ac9283b945186f8629ee7" or
        hash.sha256(0, filesize) == "8421e7995778faf1f2a902fb2c51d85ae39481f443b7b3186068d5c33c472d99" or
        hash.sha256(0, filesize) == "d293ded5a63679b81556d2c622c78be6253f500b6751d4eeb271e6500a23b21e" or
        hash.sha256(0, filesize) == "de8ddc2451fb1305d76ab20661725d11c77625aeeaa1447faf3fbf56706c87f1" or
        hash.sha256(0, filesize) == "e7ed0cd4115f3ff35c38d36cc50c6a13eba2d845554439a36108789cd1e05b17"
}

rule BulwarkBlack_apt37_deploys_ruby_jumper_campaign_to_breach_air_gapped_networks
{
    meta:
        description = "Indicators from Bulwark Black report: APT37 Deploys Ruby Jumper Campaign to Breach Air-Gapped Networks"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/apt37-deploys-ruby-jumper-campaign-to-breach-air-gapped-networks/"
        date = "2026-02-26"
        net_indicators = 13
        file_hashes = 9
    strings:
        $n0 = "144.172.106.66" ascii wide
        $n1 = "hightkdhe.store" ascii wide nocase
        $n2 = "homeatedke.store" ascii wide nocase
        $n3 = "philion.store" ascii wide nocase
        $n4 = "www.hightkdhe.store" ascii wide nocase
        $n5 = "www.homeatedke.store" ascii wide nocase
        $n6 = "www.philion.store" ascii wide nocase
        $n7 = "hightkdhe.store/star/main.php" ascii wide nocase
        $n8 = "homeatedke.store/star/main.php" ascii wide nocase
        $n9 = "https://www.hightkdhe.store/star/main.php" ascii wide nocase
        $n10 = "https://www.homeatedke.store/star/main.php" ascii wide nocase
        $n11 = "https://www.philion.store/star/main.php" ascii wide nocase
        $n12 = "philion.store/star/main.php" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "098d697f29b94c11b52c51bfe8f9c47d" or
        hash.md5(0, filesize) == "4214818d7cde26ebeb4f35bc2fc29ada" or
        hash.md5(0, filesize) == "476bce9b9a387c5f39461d781e7e22b9" or
        hash.md5(0, filesize) == "57dac5f7d21da2454d0fbefdced80bf3" or
        hash.md5(0, filesize) == "585322a931a49f4e1d78fb0b3f3c6212" or
        hash.md5(0, filesize) == "5c6ff601ccc75e76c2fc99808d8cc9a9" or
        hash.md5(0, filesize) == "709d70239f1e9441e8e21fcacfdc5d08" or
        hash.md5(0, filesize) == "ad556f4eb48e7dba6da14444dcce3170" or
        hash.md5(0, filesize) == "ed54cf1ebffbfc1c8ae1ccdd2c681012"
}

rule BulwarkBlack_diesel_vortex_russian_cybercrime_group_steals_1600_credentials_from_global_logistics_sector
{
    meta:
        description = "Indicators from Bulwark Black report: Diesel Vortex: Russian Cybercrime Group Steals 1,600+ Credentials From Global Logistics Sector"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/diesel-vortex-russian-cybercrime-group-steals-1600-credentials-from-global-logistics-sector/"
        date = "2026-02-26"
        net_indicators = 21
        file_hashes = 0
    strings:
        $n0 = "USCARGOEXPRESSyahoo.com" ascii wide nocase
        $n1 = "ernigr-esfilc.com" ascii wide nocase
        $n2 = "globalprofit-lpanel-abcdefghij.top" ascii wide nocase
        $n3 = "ipinfo.io" ascii wide nocase
        $n4 = "lpanel-bckaoplsks.top" ascii wide nocase
        $n5 = "lpanel-bumaepxuje-iframe.top" ascii wide nocase
        $n6 = "lpanel-bumaepxuje.top" ascii wide nocase
        $n7 = "lpanel-kkbnukltpo.top" ascii wide nocase
        $n8 = "ns1.suspended-domain.com" ascii wide nocase
        $n9 = "penskecar.riersrmissecured.com" ascii wide nocase
        $n10 = "penskecar.rsrmissecured.top" ascii wide nocase
        $n11 = "riersrmissecured.com" ascii wide nocase
        $n12 = "rsrmissecured.top" ascii wide nocase
        $n13 = "suspended-domain.com" ascii wide nocase
        $n14 = "t.me" ascii wide nocase
        $n15 = "yasomawork.space" ascii wide nocase
        $n16 = "ernigr-esfilc.com/security/logon[" ascii wide nocase
        $n17 = "https://ernigr-esfilc.com/security/logon.jsp?verify=7g2q978fg11jka=891FHjaH32-2f1Hnb2sF" ascii wide nocase
        $n18 = "https://penskecar.riersrmissecured.com/_c/cstm/4325/reg/DOTLookup.aspx" ascii wide nocase
        $n19 = "https://rsrmissecured.top/.git/config" ascii wide nocase
        $n20 = "penskecar.riersrmissecured.com/_c/cstm/4325/reg/DOTLookup.aspx" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_cisco_talos_exposes_three_year_campaign_uat_8616_exploits_sd_wan_zero_day_for_critical_infrastru
{
    meta:
        description = "Indicators from Bulwark Black report: Cisco Talos Exposes Three-Year Campaign: UAT-8616 Exploits SD-WAN Zero-Day for Critical Infrastructure Access"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/cisco-talos-exposes-three-year-campaign-uat-8616-exploits-sd-wan-zero-day-for-critical-infrastructure-access/"
        date = "2026-02-25"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "1.1.1.10" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_apt31s_multi_year_cyber_espionage_campaign_against_czech_ministry_of_foreign_affairs
{
    meta:
        description = "Indicators from Bulwark Black report: APT31’s Multi-Year Cyber Espionage Campaign Against Czech Ministry of Foreign Affairs"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/apt31s-multi-year-cyber-espionage-campaign-against-czech-ministry-of-foreign-affairs/"
        date = "2026-02-25"
        net_indicators = 5
        file_hashes = 0
    strings:
        $n0 = "www.treadstone71.com" ascii wide nocase
        $n1 = "https://www.treadstone71.com/cognitive-army" ascii wide nocase
        $n2 = "https://www.treadstone71.com/training/building-a-cognitive-warfare-cyber-psyops-program" ascii wide nocase
        $n3 = "https://www.treadstone71.com/training/p-omega-syllabus" ascii wide nocase
        $n4 = "https://www.treadstone71.com/training/the-mission" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_apt28_deploys_operation_macromaze_webhook_based_macro_malware_targets_european_entities
{
    meta:
        description = "Indicators from Bulwark Black report: APT28 Deploys Operation MacroMaze: Webhook-Based Macro Malware Targets European Entities"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/apt28-deploys-operation-macromaze-webhook-based-macro-malware-targets-european-entities/"
        date = "2026-02-24"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "webhook.site" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_apt28_targets_european_entities_with_operation_macromaze_webhook_malware_campaign
{
    meta:
        description = "Indicators from Bulwark Black report: APT28 Targets European Entities with Operation MacroMaze Webhook Malware Campaign"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/apt28-targets-european-entities-with-operation-macromaze-webhook-malware-campaign/"
        date = "2026-02-23"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "webhook.site" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_unit_42_exposes_active_exploitation_of_beyondtrust_cve_2026_1731_with_vshell_and_sparkrat_backdo
{
    meta:
        description = "Indicators from Bulwark Black report: Unit 42 Exposes Active Exploitation of BeyondTrust CVE-2026-1731 with VShell and SparkRAT Backdoors"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/unit-42-exposes-active-exploitation-of-beyondtrust-cve-2026-1731-with-vshell-and-sparkrat-backdoors/"
        date = "2026-02-23"
        net_indicators = 38
        file_hashes = 9
    strings:
        $n0 = "134.122.13.34" ascii wide
        $n1 = "138.197.14.95" ascii wide
        $n2 = "142.111.152.50" ascii wide
        $n3 = "144.172.103.200" ascii wide
        $n4 = "155.2.215.64" ascii wide
        $n5 = "178.128.212.209" ascii wide
        $n6 = "179.43.146.42" ascii wide
        $n7 = "23.162.40.187" ascii wide
        $n8 = "37.19.221.180" ascii wide
        $n9 = "45.61.150.96" ascii wide
        $n10 = "64.31.28.221" ascii wide
        $n11 = "64.95.10.115" ascii wide
        $n12 = "70.23.0.66" ascii wide
        $n13 = "82.29.53.187" ascii wide
        $n14 = "82.29.72.16" ascii wide
        $n15 = "83.138.53.139" ascii wide
        $n16 = "85.155.186.121" ascii wide
        $n17 = "92.223.44.134" ascii wide
        $n18 = "98.10.233.76" ascii wide
        $n19 = "39uchxifap4cvgzsuirom0szrrg.d65lre9sfqnlcv49317gcis6pyjsatzho.oast.pro" ascii wide nocase
        $n20 = "aliyundunupdate.xyz" ascii wide nocase
        $n21 = "d65sb7ngveucv5k2nm508abdsjmbn7qmn.oast.pro" ascii wide nocase
        $n22 = "judiemkqjajsfzpidfjlowgl8nyrtd49x.oast.fun" ascii wide nocase
        $n23 = "oastify.com" ascii wide nocase
        $n24 = "q0r2e5q2dzbykcox9qmkptm12s8mwb.oastify.com" ascii wide nocase
        $n25 = "transfer.weepee.io" ascii wide nocase
        $n26 = "http://134.122.13.34:8979/c" ascii wide nocase
        $n27 = "http://39uchxifap4cvgzsuirom0szrrg.d65lre9sfqnlcv49317gcis6pyjsatzho.oast.pro" ascii wide nocase
        $n28 = "http://64.31.28.221/support" ascii wide nocase
        $n29 = "http://82.29.53.187:8778/app_cli" ascii wide nocase
        $n30 = "http://85.155.186.121/access" ascii wide nocase
        $n31 = "https://64.95.10.115:23011/update.sh" ascii wide nocase
        $n32 = "https://85.155.186.121/access/Remote%20Access-linux64-offline.tar?language=en&amp;app=76049110434275449312180081368257747094" ascii wide nocase
        $n33 = "https://judiemkqjajsfzpidfjlowgl8nyrtd49x.oast.fun" ascii wide nocase
        $n34 = "https://transfer.weepee.io/7nZw7/blue.drx" ascii wide nocase
        $n35 = "oast.fun" ascii wide nocase
        $n36 = "oast.pro" ascii wide nocase
        $n37 = "weepee.io/7nZw7/blue.drx" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "0ecc867ce916d01640d76ec03de24d1d23585eb582e9c48a0364c62a590548ac" or
        hash.sha256(0, filesize) == "4762e944a0ce1f9aef243e11538f84f16b6f36560ed6e32dfd9a5f99e17e8e50" or
        hash.sha256(0, filesize) == "66cceb2c2f1d9988b501832fd3b559775982e2fce4ab38fc4ffe71b74eafc726" or
        hash.sha256(0, filesize) == "679ee05d92a858b6fe70aeb6072eb804548f1732e18b6c181af122b833386afb" or
        hash.sha256(0, filesize) == "98442387d466f27357d727b3706037a4df12a78602b93df973b063462a677761" or
        hash.sha256(0, filesize) == "98a7b0900a9072bb40af579ec372da7b27af12b15868394df51fefe290ab176b" or
        hash.sha256(0, filesize) == "9f431d5549a03aee92cfd2bdbbe90f1c91e965c99e90a0c9ad5a001f4e80c350" or
        hash.sha256(0, filesize) == "cc2bc3750cc5125a50466f66ae4f2bedf1cac0e43477a78ed2fd88f3e987a292" or
        hash.sha256(0, filesize) == "cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce"
}

rule BulwarkBlack_facebook_malvertising_campaign_uses_fake_windows_11_pages_to_deploy_credential_stealing_malware
{
    meta:
        description = "Indicators from Bulwark Black report: Facebook Malvertising Campaign Uses Fake Windows 11 Pages to Deploy Credential-Stealing Malware"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/facebook-malvertising-campaign-uses-fake-windows-11-pages-to-deploy-credential-stealing-malware/"
        date = "2026-02-21"
        net_indicators = 4
        file_hashes = 1
    strings:
        $n0 = "ms-25h2-download.pro" ascii wide nocase
        $n1 = "ms-25h2-update.pro" ascii wide nocase
        $n2 = "ms25h2-download.pro" ascii wide nocase
        $n3 = "ms25h2-update.pro" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "c634838f255e0a691f8be3eab45f2015f7f3572fba2124142cf9fe1d227416aa"
}

rule BulwarkBlack_kimwolf_botnet_swamps_i2p_anonymity_network_in_massive_sybil_attack
{
    meta:
        description = "Indicators from Bulwark Black report: Kimwolf Botnet Swamps I2P Anonymity Network in Massive Sybil Attack"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/kimwolf-botnet-swamps-i2p-anonymity-network-in-massive-sybil-attack/"
        date = "2026-02-20"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "geti2p.net" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_threat_actors_abuse_atlassian_jira_cloud_to_bypass_email_security_and_target_government_entities
{
    meta:
        description = "Indicators from Bulwark Black report: Threat Actors Abuse Atlassian Jira Cloud to Bypass Email Security and Target Government Entities"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/threat-actors-abuse-atlassian-jira-cloud-to-bypass-email-security-and-target-government-entities/"
        date = "2026-02-18"
        net_indicators = 8
        file_hashes = 0
    strings:
        $n0 = "13.227.180.4" ascii wide
        $n1 = "adrinal.com" ascii wide nocase
        $n2 = "archicad3d.com" ascii wide nocase
        $n3 = "atlassian.net" ascii wide nocase
        $n4 = "barankinyserialxud.online" ascii wide nocase
        $n5 = "claude.ai" ascii wide nocase
        $n6 = "go.sparkpostmail1.com" ascii wide nocase
        $n7 = "sparkpostmail1.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_physical_mail_phishing_targets_trezor_and_ledger_users_attackers_use_qr_codes_to_steal_recovery_
{
    meta:
        description = "Indicators from Bulwark Black report: Physical Mail Phishing Targets Trezor and Ledger Users: Attackers Use QR Codes to Steal Recovery Phrases"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/physical-mail-phishing-targets-trezor-and-ledger-users-attackers-use-qr-codes-to-steal-recovery-phrases/"
        date = "2026-02-16"
        net_indicators = 8
        file_hashes = 0
    strings:
        $n0 = "ledger.setuptransactioncheck.com" ascii wide nocase
        $n1 = "trezor.authentication-check.io" ascii wide nocase
        $n2 = "authentication-check.io/" ascii wide nocase
        $n3 = "authentication-check.io/black/api/send.php" ascii wide nocase
        $n4 = "https://ledger.setuptransactioncheck.com/" ascii wide nocase
        $n5 = "https://trezor.authentication-check.io/" ascii wide nocase
        $n6 = "https://trezor.authentication-check.io/black/api/send.php" ascii wide nocase
        $n7 = "setuptransactioncheck.com/" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_microsoft_exposes_dns_based_clickfix_attack_nslookup_commands_used_for_stealth_malware_staging
{
    meta:
        description = "Indicators from Bulwark Black report: Microsoft Exposes DNS-Based ClickFix Attack: Nslookup Commands Used for Stealth Malware Staging"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/microsoft-exposes-dns-based-clickfix-attack-nslookup-commands-used-for-stealth-malware-staging/"
        date = "2026-02-15"
        net_indicators = 3
        file_hashes = 0
    strings:
        $n0 = "azwsappdev.com" ascii wide nocase
        $n1 = "raxelpak.com" ascii wide nocase
        $n2 = "testdomain123123.shop" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_critical_unstructured_io_vulnerability_cve_2025_64712_threatens_ai_pipelines_at_amazon_google_an
{
    meta:
        description = "Indicators from Bulwark Black report: Critical Unstructured.io Vulnerability CVE-2025-64712 Threatens AI Pipelines at Amazon, Google, and Fortune 1000 Enterprises"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/critical-unstructured-io-vulnerability-cve-2025-64712-threatens-ai-pipelines-at-amazon-google-and-fortune-1000-enterprises/"
        date = "2026-02-14"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "Unstructured.io" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_metro4shell_critical_react_native_cli_vulnerability_actively_exploited_to_deploy_malware
{
    meta:
        description = "Indicators from Bulwark Black report: Metro4Shell: Critical React Native CLI Vulnerability Actively Exploited to Deploy Malware"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/metro4shell-critical-react-native-cli-vulnerability-actively-exploited-to-deploy-malware/"
        date = "2026-02-13"
        net_indicators = 3
        file_hashes = 0
    strings:
        $n0 = "134.209.69.155" ascii wide
        $n1 = "223.6.249.141" ascii wide
        $n2 = "5.109.182.231" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_aiframe_campaign_30_fake_ai_chrome_extensions_with_300k_users_steal_credentials_gmail_content
{
    meta:
        description = "Indicators from Bulwark Black report: AiFrame Campaign: 30 Fake AI Chrome Extensions with 300K Users Steal Credentials, Gmail Content"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/aiframe-campaign-30-fake-ai-chrome-extensions-with-300k-users-steal-credentials-gmail-content/"
        date = "2026-02-12"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "tapnetic.pro" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_xworm_rat_campaign_exploits_cve_2018_0802_in_multi_language_phishing_attacks_using_fileless_inje
{
    meta:
        description = "Indicators from Bulwark Black report: XWorm RAT Campaign Exploits CVE-2018-0802 in Multi-Language Phishing Attacks Using Fileless Injection"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/xworm-rat-campaign-exploits-cve-2018-0802-in-multi-language-phishing-attacks-using-fileless-injection/"
        date = "2026-02-11"
        net_indicators = 15
        file_hashes = 6
    strings:
        $n0 = "berlin101.com" ascii wide nocase
        $n1 = "cloudinary.com" ascii wide nocase
        $n2 = "pub-3bc1de741f8149f49bdbafa703067f24.r2.dev" ascii wide nocase
        $n3 = "r2.dev" ascii wide nocase
        $n4 = "res.cloudinary.com" ascii wide nocase
        $n5 = "retrodayaengineering.icu" ascii wide nocase
        $n6 = "http://pub-3bc1de741f8149f49bdbafa703067f24.r2.dev/wwa.txt" ascii wide nocase
        $n7 = "https://pub-3bc1de741f8149f49bdbafa703067f24.r2.dev/wwa.txt" ascii wide nocase
        $n8 = "https://res.cloudinary.com/dbjtzqp4q/image/upload/v1767455040/" ascii wide nocase
        $n9 = "https://res.cloudinary.com/dbjtzqp4q/image/upload/v1767455040/optimized_MSI_lpsd9p.jpg" ascii wide nocase
        $n10 = "https://retrodayaengineering.icu/HGG.hta" ascii wide nocase
        $n11 = "pub-3bc1de741f8149f49bdbafa703067f24.r2.dev/wwa.txt" ascii wide nocase
        $n12 = "res.cloudinary.com/dbjtzqp4q/image/upload/v1767455040/" ascii wide nocase
        $n13 = "res.cloudinary.com/dbjtzqp4q/image/upload/v1767455040/optimized_MSI_lpsd9p.jpg" ascii wide nocase
        $n14 = "retrodayaengineering.icu/HGG.hta" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "3bc1de741f8149f49bdbafa703067f24" or
        hash.sha256(0, filesize) == "3f4c3c16f63fb90d1fd64b031d8a9803035f3cb18332e198850896881fb42fe5" or
        hash.sha256(0, filesize) == "8665bc1b33cbe6f5859cd6e362af77738ba73a6e6d4b9974c16c8521d84c1892" or
        hash.sha256(0, filesize) == "eacd8e95ead3ffe2c225768ef6f85672c4bfdf61655ed697b97f598203ef2cf6" or
        hash.sha256(0, filesize) == "ee663d016894d44c69b1fdc9d2a5be02f028a56fc22b694ff7c1dacb2bbbcc6d" or
        hash.sha256(0, filesize) == "fd9ba9e6bd4886edc1123d4074d0eac363df61162364530b1303390aa621140b"
}

rule BulwarkBlack_bluenoroffs_ghostcall_and_ghosthire_campaigns_use_stolen_victim_videos_to_compromise_crypto_exec
{
    meta:
        description = "Indicators from Bulwark Black report: BlueNoroff’s GhostCall and GhostHire Campaigns Use Stolen Victim Videos to Compromise Crypto Executives"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/bluenoroffs-ghostcall-and-ghosthire-campaigns-use-stolen-victim-videos-to-compromise-crypto-executives/"
        date = "2026-02-10"
        net_indicators = 102
        file_hashes = 65
    strings:
        $n0 = "104.168.214.151" ascii wide
        $n1 = "Backdoor.Python.Agent.br" ascii wide nocase
        $n2 = "Crypto.com" ascii wide nocase
        $n3 = "Trojan.Shell.Agent.gn" ascii wide nocase
        $n4 = "autoupdate.online" ascii wide nocase
        $n5 = "bots.autoupdate.online" ascii wide nocase
        $n6 = "botsc.autoupdate.xyz" ascii wide nocase
        $n7 = "check.datatabletemplate.shop" ascii wide nocase
        $n8 = "chkactive.online" ascii wide nocase
        $n9 = "cloud-server.store" ascii wide nocase
        $n10 = "dataupload.store" ascii wide nocase
        $n11 = "download.datatabletemplate.xyz" ascii wide nocase
        $n12 = "download.face-online.world" ascii wide nocase
        $n13 = "file-server.store" ascii wide nocase
        $n14 = "filedrive.online" ascii wide nocase
        $n15 = "first.longlastfor.online" ascii wide nocase
        $n16 = "first.system-update.xyz" ascii wide nocase
        $n17 = "firstfromsep.online" ascii wide nocase
        $n18 = "flashserve.store" ascii wide nocase
        $n19 = "group.com" ascii wide nocase
        $n20 = "image-support.xyz" ascii wide nocase
        $n21 = "instant-update.online" ascii wide nocase
        $n22 = "metamask.awaitingfor.site" ascii wide nocase
        $n23 = "pre.alwayswait.site" ascii wide nocase
        $n24 = "readysafe.xyz" ascii wide nocase
        $n25 = "real-update.xyz" ascii wide nocase
        $n26 = "root.chkstate.online" ascii wide nocase
        $n27 = "root.security-update.xyz" ascii wide nocase
        $n28 = "safefor.xyz" ascii wide nocase
        $n29 = "safeup.store" ascii wide nocase
        $n30 = "safeupload.online" ascii wide nocase
        $n31 = "second.awaitingfor.online" ascii wide nocase
        $n32 = "second.systemupdate.cloud" ascii wide nocase
        $n33 = "secondshop.online" ascii wide nocase
        $n34 = "secondshop.store" ascii wide nocase
        $n35 = "signsafe.site" ascii wide nocase
        $n36 = "signsafe.xyz" ascii wide nocase
        $n37 = "support.ms" ascii wide nocase
        $n38 = "support.ms-live.us" ascii wide nocase
        $n39 = "support.video-meeting.online" ascii wide nocase
        $n40 = "swissborg.blog" ascii wide nocase
        $n41 = "system.updatecheck.store" ascii wide nocase
        $n42 = "urgent-update.cloud" ascii wide nocase
        $n43 = "us.zoom.com" ascii wide nocase
        $n44 = "web071zoom.us" ascii wide nocase
        $n45 = "web.commoncome.online" ascii wide nocase
        $n46 = "writeup.live" ascii wide nocase
        $n47 = "zoom.app" ascii wide nocase
        $n48 = "alwayswait.site" ascii wide nocase
        $n49 = "autoupdate.xyz" ascii wide nocase
        $n50 = "awaitingfor.online" ascii wide nocase
        $n51 = "awaitingfor.site/update" ascii wide nocase
        $n52 = "chkactive.online/update" ascii wide nocase
        $n53 = "chkstate.online" ascii wide nocase
        $n54 = "cloud-server.store/update" ascii wide nocase
        $n55 = "commoncome.online" ascii wide nocase
        $n56 = "datatabletemplate.shop" ascii wide nocase
        $n57 = "datatabletemplate.xyz" ascii wide nocase
        $n58 = "datatabletemplate.xyz/account/register/id=8118555902061899&amp" ascii wide nocase
        $n59 = "dataupload.store/uploadfiles" ascii wide nocase
        $n60 = "face-online.world" ascii wide nocase
        $n61 = "file-server.store/update" ascii wide nocase
        $n62 = "filedrive.online/uploadfiles" ascii wide nocase
        $n63 = "firstfromsep.online/client" ascii wide nocase
        $n64 = "flashserve.store/update" ascii wide nocase
        $n65 = "http://web071zoom.us/fix/audio-fv/7217417464" ascii wide nocase
        $n66 = "http://web071zoom.us/fix/audio-tr/7217417464" ascii wide nocase
        $n67 = "http://web071zoom.us/fix/audio/4542828056" ascii wide nocase
        $n68 = "https://bots.autoupdate.online:8080/test" ascii wide nocase
        $n69 = "https://chkactive.online/update" ascii wide nocase
        $n70 = "https://cloud-server.store/update" ascii wide nocase
        $n71 = "https://dataupload.store/uploadfiles" ascii wide nocase
        $n72 = "https://download.datatabletemplate.xyz/account/register/id=8118555902061899&amp;secret=QwLoOZSDakFh" ascii wide nocase
        $n73 = "https://file-server.store/update" ascii wide nocase
        $n74 = "https://filedrive.online/uploadfiles" ascii wide nocase
        $n75 = "https://flashserve.store/update" ascii wide nocase
        $n76 = "https://metamask.awaitingfor.site/update" ascii wide nocase
        $n77 = "https://safeup.store/test" ascii wide nocase
        $n78 = "https://safeupload.online/uploadfiles" ascii wide nocase
        $n79 = "https://support.ms-live.us/301631/check" ascii wide nocase
        $n80 = "https://support.ms-live.us/register/22989524464UcX2b5w52" ascii wide nocase
        $n81 = "https://support.ms-live.us/update/02583235891M49FYUN57" ascii wide nocase
        $n82 = "https://urgent-update.cloud/uploadfiles" ascii wide nocase
        $n83 = "https://writeup.live/test" ascii wide nocase
        $n84 = "longlastfor.online" ascii wide nocase
        $n85 = "ms-live.us/301631/check" ascii wide nocase
        $n86 = "ms-live.us/register/22989524464UcX2b5w52" ascii wide nocase
        $n87 = "ms-live.us/update/02583235891M49FYUN57" ascii wide nocase
        $n88 = "safeup.store/test" ascii wide nocase
        $n89 = "safeupload.online/uploadfiles" ascii wide nocase
        $n90 = "security-update.xyz" ascii wide nocase
        $n91 = "signsafe.xyz/update" ascii wide nocase
        $n92 = "system-update.xyz" ascii wide nocase
        $n93 = "systemupdate.cloud" ascii wide nocase
        $n94 = "systemupdate.cloud/client" ascii wide nocase
        $n95 = "updatecheck.store" ascii wide nocase
        $n96 = "urgent-update.cloud/uploadfiles" ascii wide nocase
        $n97 = "video-meeting.online" ascii wide nocase
        $n98 = "web071zoom.us/fix/audio-fv/7217417464" ascii wide nocase
        $n99 = "web071zoom.us/fix/audio-tr/7217417464" ascii wide nocase
        $n100 = "web071zoom.us/fix/audio/4542828056" ascii wide nocase
        $n101 = "writeup.live/test" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "00dd47af3db45548d2722fe8a4489508" or
        hash.md5(0, filesize) == "01d3ed1c228f09d8e56bfbc5f5622a6c" or
        hash.md5(0, filesize) == "0af11f610da1f691e43173d44643283f" or
        hash.md5(0, filesize) == "0ca37675d75af0e7def0025cd564d6c5" or
        hash.md5(0, filesize) == "10cd1ef394bc2a2d8d8f2558b73ac7b8" or
        hash.md5(0, filesize) == "1243968876262c3ad4250e1371447b23" or
        hash.md5(0, filesize) == "1653d75d579872fadec1f22cf7fee3c0" or
        hash.md5(0, filesize) == "17baae144d383e4dc32f1bf69700e587" or
        hash.md5(0, filesize) == "19a7e16332a6860b65e6944f1f3c5001" or
        hash.md5(0, filesize) == "1ee10fa01587cec51f455ceec779a160" or
        hash.md5(0, filesize) == "261a409946b6b4d9ce706242a76134e3" or
        hash.md5(0, filesize) == "2b499eb3865a7ef17264d15252b7f73e" or
        hash.md5(0, filesize) == "2c42253ebf9a743814b9b16a89522bef" or
        hash.md5(0, filesize) == "31b88dd319af8e4b8a96fc9732ebc708" or
        hash.md5(0, filesize) == "358c2969041c8be74ce478edb2ffcd19" or
        hash.md5(0, filesize) == "389447013870120775556bb4519dba97" or
        hash.md5(0, filesize) == "38c8d80dd32d00e9c9440a498f7dd739" or
        hash.md5(0, filesize) == "3bbe4dfe3134c8a7928d10c948e20bee" or
        hash.md5(0, filesize) == "50f341b24cb75f37d042d1e5f9e3e5aa" or
        hash.md5(0, filesize) == "529fe6eff1cf452680976087e2250c02" or
        hash.md5(0, filesize) == "5ad40a5fd18a1b57b69c44bc2963dc6b" or
        hash.md5(0, filesize) == "5cb4f0084f3c25e640952753ed5b25d0" or
        hash.md5(0, filesize) == "60bfe4f378e9f5a84183ac505a032228" or
        hash.md5(0, filesize) == "6348b49f3499d760797247b94385fda3" or
        hash.md5(0, filesize) == "6422795a6df10c45c1006f92d686ee7e" or
        hash.md5(0, filesize) == "6aa93664b4852cb5bad84ba1a187f645" or
        hash.md5(0, filesize) == "7168ce5c6e5545a5b389db09c90038da" or
        hash.md5(0, filesize) == "73d26eb56e5a3426884733c104c3f625" or
        hash.md5(0, filesize) == "7581854ff6c890684823f3aed03c210f" or
        hash.md5(0, filesize) == "76ace3a6892c25512b17ed42ac2ebd05" or
        hash.md5(0, filesize) == "7e50c3f301dd045eb189ba1644ded155" or
        hash.md5(0, filesize) == "7f94ed2d5f566c12de5ebe4b5e3d8aa3" or
        hash.md5(0, filesize) == "8006efb8dd703073197e5a27682b35bf" or
        hash.md5(0, filesize) == "8f8942cd14f646f59729f83cbd4c357b" or
        hash.md5(0, filesize) == "931cec3c80c78d233e3602a042a2e71b" or
        hash.md5(0, filesize) == "9551b4af789b2db563f9452eaf46b6aa" or
        hash.md5(0, filesize) == "963f473f1734d8b3fbb8c9a227c06d07" or
        hash.md5(0, filesize) == "a070b77c5028d7a5d2895f1c9d35016f" or
        hash.md5(0, filesize) == "a0eb7e480752d494709c63aa35ccf36c" or
        hash.md5(0, filesize) == "a26f2b97ca4e2b4b5d58933900f02131" or
        hash.md5(0, filesize) == "a6ce961f487b4cbdfe68d0a249647c48" or
        hash.md5(0, filesize) == "ab1e8693931f8c694247d96cf5a85197" or
        hash.md5(0, filesize) == "b2e9a6412fd7c068a5d7c38d0afd946f" or
        hash.md5(0, filesize) == "b567bfdaac131a2d8a23ad8fd450a31d" or
        hash.md5(0, filesize) == "c42c7a2ea1c2f00dddb0cc4c8bfb5bcf" or
        hash.md5(0, filesize) == "c446682f33641cff21083ac2ce477dbe" or
        hash.md5(0, filesize) == "c6f0c8d41b9ad4f079161548d2435d80" or
        hash.md5(0, filesize) == "d63805e89053716b6ab93ce6decf8450" or
        hash.md5(0, filesize) == "d8529855fab4b4aa6c2b34449cb3b9fb" or
        hash.md5(0, filesize) == "de93e85199240de761a8ba0a56f0088d" or
        hash.md5(0, filesize) == "e33f942cf1479ca8530a916868bad954" or
        hash.md5(0, filesize) == "e8680d17fba6425e4a9bb552fb8db2b1" or
        hash.md5(0, filesize) == "e9fdd703e60b31eb803b1b59985cabec" or
        hash.md5(0, filesize) == "eda0525c078f5a216a977bc64e86160a" or
        hash.md5(0, filesize) == "f1bad0efbd3bd5a4202fe740756f977a" or
        hash.md5(0, filesize) == "f1d2af27b13cd3424556b18dfd3cf83f" or
        hash.md5(0, filesize) == "f8bb2528bf35f8c11fbc4369e68c4038" or
        hash.sha256(0, filesize) == "3dd226d0b700f33974f409142defb62a8cd172ae5f2eb9beb7f5750eb1702e2a" or
        hash.sha256(0, filesize) == "4451ee8bc53ea7c148d8348bc7b82aca9977bdd31c0156dfe25c4a879a1d2190" or
        hash.sha256(0, filesize) == "5b77f83ecefa0e32ba922f61c9efff7f755ba51a010db844ca7e8ad3db28650a" or
        hash.sha256(0, filesize) == "71b743c529f0b27735f7774a0903cb908edc93423b60fe9be49a3729982d0e8d" or
        hash.sha256(0, filesize) == "a6c1a7ce43b029a1ef4ae69b26f745440ecce8368c89f11ac999d4ed04a31572" or
        hash.sha256(0, filesize) == "b3cc15c1033de79024f9cf3cd6a6a7a9b7e54a1a57d3156036f5c05f541694b7" or
        hash.sha256(0, filesize) == "b494a0ae421afe170f6cb9de2c1193a78fbe16f627f85139676afc5d9bfe93a2" or
        hash.sha256(0, filesize) == "c4db903322d17c8cbf1d1db55124854c0b070d6ece54162b6a4d06df24c572df"
}

rule BulwarkBlack_apt28_exploits_cve_2026_21509_in_operation_neusploit_stealing_emails_with_minidoor_backdoor
{
    meta:
        description = "Indicators from Bulwark Black report: APT28 Exploits CVE-2026-21509 in Operation Neusploit: Stealing Emails with MiniDoor Backdoor"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/apt28-exploits-cve-2026-21509-in-operation-neusploit-stealing-emails-with-minidoor-backdoor/"
        date = "2026-02-10"
        net_indicators = 8
        file_hashes = 36
    strings:
        $n0 = "freefoodaid.com" ascii wide nocase
        $n1 = "wellnesscaremed.com" ascii wide nocase
        $n2 = "freefoodaid.com/documents/2_2.d" ascii wide nocase
        $n3 = "freefoodaid.com/documents/2_2.lNk" ascii wide nocase
        $n4 = "freefoodaid.com/tables/tables.d" ascii wide nocase
        $n5 = "https://freefoodaid.com/documents/2_2.d" ascii wide nocase
        $n6 = "https://freefoodaid.com/documents/2_2.lNk" ascii wide nocase
        $n7 = "https://freefoodaid.com/tables/tables.d" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "154ff6774294e0e6a46581c8452a77de" or
        hash.md5(0, filesize) == "2f7b4dca1c79e525aef8da537294a6c4" or
        hash.md5(0, filesize) == "4727582023cd8071a6f388ea3ba2feaa" or
        hash.md5(0, filesize) == "7c396677848776f9824ebe408bbba943" or
        hash.md5(0, filesize) == "859c4b85ed85e6cc4eadb1a037a61e16" or
        hash.md5(0, filesize) == "95e59536455a089ced64f5af2539a449" or
        hash.md5(0, filesize) == "d47261e52335b516a777da368208ee91" or
        hash.md5(0, filesize) == "e4a5c4b205e1b80dc20d9a2fb4126d06" or
        hash.md5(0, filesize) == "ea6615942f2c23dba7810a6f7d69e2da" or
        hash.md5(0, filesize) == "ee0b44346db028a621d1dec99f429823" or
        hash.md5(0, filesize) == "f05d0b13c633ad889334781cf4091d3e" or
        hash.md5(0, filesize) == "f3b869a8d5ad243e35963ba6d7f89855" or
        hash.sha1(0, filesize) == "22da6a104149cad87d5ec5da4c3153bebf68c411" or
        hash.sha1(0, filesize) == "23b6f9c00b9d5475212173ec3cbbcff34c4400a7" or
        hash.sha1(0, filesize) == "4592e6173a643699dc526778aa0a30330d16fe08" or
        hash.sha1(0, filesize) == "7bbb530eb77c6416f02813cd2764e49bd084465c" or
        hash.sha1(0, filesize) == "d577c4a264fee27084ddf717441eb89f714972a5" or
        hash.sha1(0, filesize) == "c1b272067491258ea4a2b1d2789d82d157aaf90a" or
        hash.sha1(0, filesize) == "c4799d17a4343bd353e0edb0a4de248b99295d4d" or
        hash.sha1(0, filesize) == "c8c84bf33c05fb3a69bc5e2d6377b73649b93dce" or
        hash.sha1(0, filesize) == "cea7e9323d79054f92634f4032c26d30c1cedd7e" or
        hash.sha1(0, filesize) == "d788d85335e20bb1f173d4d0494629d36083dddc" or
        hash.sha1(0, filesize) == "da1c3e92f69e6ca0e4f4823525905cb6969a44ad" or
        hash.sha1(0, filesize) == "e52a9f004f4359ea0f8f9c6eb91731ed78e5c4d3" or
        hash.sha256(0, filesize) == "0bb0d54033767f081cae775e3cf9ede7ae6bea75f35fbfb748ccba9325e28e5e" or
        hash.sha256(0, filesize) == "1ed863a32372160b3a25549aad25d48d5352d9b4f58d4339408c4eea69807f50" or
        hash.sha256(0, filesize) == "2822c72a59b58c00fc088aa551cdeeb92ca10fd23e23745610ff207f53118db9" or
        hash.sha256(0, filesize) == "3f446d316efe2514efd70c975d0c87e12357db9fca54a25834d60b28192c6a69" or
        hash.sha256(0, filesize) == "5a17cfaea0cc3a82242fdd11b53140c0b56256d769b07c33757d61e0a0a6ec02" or
        hash.sha256(0, filesize) == "9f4672c1374034ac4556264f0d4bf96ee242c0b5a9edaa4715b5e61fe8d55cc8" or
        hash.sha256(0, filesize) == "a876f648991711e44a8dcf888a271880c6c930e5138f284cd6ca6128eca56ba1" or
        hash.sha256(0, filesize) == "a944a09783023a2c6c62d3601cbd5392a03d808a6a51728e07a3270861c2a8ee" or
        hash.sha256(0, filesize) == "b2ba51b4491da8604ff9410d6e004971e3cd9a321390d0258e294ac42010b546" or
        hash.sha256(0, filesize) == "bb23545380fde9f48ad070f88fe0afd695da5fcae8c5274814858c5a681d8c4e" or
        hash.sha256(0, filesize) == "c91183175ce77360006f964841eb4048cf37cb82103f2573e262927be4c7607f" or
        hash.sha256(0, filesize) == "fd3f13db41cd5b442fa26ba8bc0e9703ed243b3516374e3ef89be71cbf07436b"
}

rule BulwarkBlack_fake_7_zip_downloads_convert_home_pcs_into_residential_proxy_nodes_for_cybercriminals
{
    meta:
        description = "Indicators from Bulwark Black report: Fake 7-Zip Downloads Convert Home PCs Into Residential Proxy Nodes for Cybercriminals"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/fake-7-zip-downloads-convert-home-pcs-into-residential-proxy-nodes-for-cybercriminals/"
        date = "2026-02-09"
        net_indicators = 15
        file_hashes = 3
    strings:
        $n0 = "7-zip.org" ascii wide nocase
        $n1 = "7zip.com" ascii wide nocase
        $n2 = "apex.herosms.ai" ascii wide nocase
        $n3 = "flux.smshero.co" ascii wide nocase
        $n4 = "iplogger.org" ascii wide nocase
        $n5 = "neo.herosms.co" ascii wide nocase
        $n6 = "nova.smshero.ai" ascii wide nocase
        $n7 = "soc.hero-sms.co" ascii wide nocase
        $n8 = "spark.herosms.io" ascii wide nocase
        $n9 = "hero-sms.co" ascii wide nocase
        $n10 = "herosms.ai" ascii wide nocase
        $n11 = "herosms.co" ascii wide nocase
        $n12 = "herosms.io" ascii wide nocase
        $n13 = "smshero.ai" ascii wide nocase
        $n14 = "smshero.co" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "3544ffefb2a38bf4faf6181aa4374f4c186d3c2a7b9b059244b65dce8d5688d9" or
        hash.sha256(0, filesize) == "b7a7013b951c3cea178ece3363e3dd06626b9b98ee27ebfd7c161d0bbcfbd894" or
        hash.sha256(0, filesize) == "e7291095de78484039fdc82106d191bf41b7469811c4e31b4228227911d25027"
}

rule BulwarkBlack_tgr_sta_1030_espionage_campaign_compromises_70_organizations_across_37_nations_using_shadowguard
{
    meta:
        description = "Indicators from Bulwark Black report: TGR-STA-1030 Espionage Campaign Compromises 70 Organizations Across 37 Nations Using ShadowGuard Linux Rootkit"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/tgr-sta-1030-espionage-campaign-compromises-70-organizations-across-37-nations-using-shadowguard-linux-rootkit/"
        date = "2026-02-09"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "mega.nz" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_bridgepay_ransomware_attack_forces_nationwide_cash_only_payment_disruption
{
    meta:
        description = "Indicators from Bulwark Black report: BridgePay Ransomware Attack Forces Nationwide Cash-Only Payment Disruption"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/bridgepay-ransomware-attack-forces-nationwide-cash-only-payment-disruption/"
        date = "2026-02-08"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "Gateway.Itstgate.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_flickr_data_breach_exposes_user_information_through_third_party_email_vendor_vulnerability
{
    meta:
        description = "Indicators from Bulwark Black report: Flickr Data Breach Exposes User Information Through Third-Party Email Vendor Vulnerability"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/flickr-data-breach-exposes-user-information-through-third-party-email-vendor-vulnerability/"
        date = "2026-02-08"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "Winbuzzer.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_apt_q_27_goldeneyedog_deploys_fileless_malware_in_stealthy_corporate_network_attacks
{
    meta:
        description = "Indicators from Bulwark Black report: APT-Q-27 (GoldenEyeDog) Deploys Fileless Malware in Stealthy Corporate Network Attacks"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/apt-q-27-goldeneyedog-deploys-fileless-malware-in-stealthy-corporate-network-attacks/"
        date = "2026-02-07"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "185.135.79.200" ascii wide
        $n1 = "wk.goldeyeuu.io" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_systembc_botnet_survives_law_enforcement_takedown_infects_over_10000_devices_worldwide
{
    meta:
        description = "Indicators from Bulwark Black report: SystemBC Botnet Survives Law Enforcement Takedown, Infects Over 10,000 Devices Worldwide"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/systembc-botnet-survives-law-enforcement-takedown-infects-over-10000-devices-worldwide/"
        date = "2026-02-05"
        net_indicators = 24
        file_hashes = 3
    strings:
        $n0 = "103.112.211.167" ascii wide
        $n1 = "103.28.36.105" ascii wide
        $n2 = "148.113.208.227" ascii wide
        $n3 = "185.93.89.145" ascii wide
        $n4 = "196.13.207.92" ascii wide
        $n5 = "202.142.184.234" ascii wide
        $n6 = "36.255.98.152" ascii wide
        $n7 = "36.255.98.159" ascii wide
        $n8 = "36.255.98.160" ascii wide
        $n9 = "36.255.98.165" ascii wide
        $n10 = "36.255.98.179" ascii wide
        $n11 = "62.60.131.180" ascii wide
        $n12 = "62.60.131.184" ascii wide
        $n13 = "62.60.131.187" ascii wide
        $n14 = "62.60.131.191" ascii wide
        $n15 = "62.60.131.204" ascii wide
        $n16 = "bthoster.com" ascii wide nocase
        $n17 = "concours.gov" ascii wide nocase
        $n18 = "concours.gov.bf" ascii wide nocase
        $n19 = "exploit.in" ascii wide nocase
        $n20 = "forum.exploit.in" ascii wide nocase
        $n21 = "gov.vn" ascii wide nocase
        $n22 = "phutho.duchop.gov.vn" ascii wide nocase
        $n23 = "duchop.gov.vn" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "0f5c81eaf35755a52e670c89b9546e7047828d83f346e3c29be1f6958e14a384" or
        hash.sha256(0, filesize) == "c729bf6ea292116b3477da4843aaeec73370e2bd46e7a27674671e9a65fb473a" or
        hash.sha256(0, filesize) == "da95384032f84228ef62f982f3c0f9e574dc6b06b606db33889ea6a5f93d6ae2"
}

rule BulwarkBlack_dknife_cisco_talos_exposes_china_nexus_gateway_monitoring_aitm_framework_active_since_2019
{
    meta:
        description = "Indicators from Bulwark Black report: DKnife: Cisco Talos Exposes China-Nexus Gateway-Monitoring AitM Framework Active Since 2019"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/dknife-cisco-talos-exposes-china-nexus-gateway-monitoring-aitm-framework-active-since-2019/"
        date = "2026-02-05"
        net_indicators = 3
        file_hashes = 1
    strings:
        $n0 = "Hunt.io" ascii wide nocase
        $n1 = "malpedia.caad.fkie.fraunhofer.de" ascii wide nocase
        $n2 = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shadowpad&quot" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha1(0, filesize) == "a182e35da64e6d71cb55f125c4d4225196523f14"
}

rule BulwarkBlack_encase_forensic_driver_weaponized_byovd_attack_targets_59_edr_tools_through_sonicwall_vpn_breach
{
    meta:
        description = "Indicators from Bulwark Black report: EnCase Forensic Driver Weaponized: BYOVD Attack Targets 59 EDR Tools Through SonicWall VPN Breach"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/encase-forensic-driver-weaponized-byovd-attack-targets-59-edr-tools-through-sonicwall-vpn-breach/"
        date = "2026-02-05"
        net_indicators = 3
        file_hashes = 2
    strings:
        $n0 = "193.160.216.221" ascii wide
        $n1 = "69.10.60.250" ascii wide
        $n2 = "OemHwUpd.sy" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "3111f4d7d4fac55103453c4c8adb742def007b96b7c8ed265347df97137fbee0" or
        hash.sha256(0, filesize) == "6a6aaeed4a6bbe82a08d197f5d40c2592a461175f181e0440e0ff45d5fb60939"
}

rule BulwarkBlack_pdfsider_the_stealthy_backdoor_targeting_fortune_100_financial_institutions
{
    meta:
        description = "Indicators from Bulwark Black report: PDFSider: The Stealthy Backdoor Targeting Fortune 100 Financial Institutions"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/pdfsider-the-stealthy-backdoor-targeting-fortune-100-financial-institutions/"
        date = "2026-02-04"
        net_indicators = 7
        file_hashes = 0
    strings:
        $n0 = "Booking.com" ascii wide nocase
        $n1 = "BugsBounty.com" ascii wide nocase
        $n2 = "Builder.ai" ascii wide nocase
        $n3 = "Coinopsy.com" ascii wide nocase
        $n4 = "Collectibles.com" ascii wide nocase
        $n5 = "Discord.io" ascii wide nocase
        $n6 = "Duck.ai" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_shinyhunters_claims_massive_ivy_league_breach_2_2_million_records_from_harvard_and_upenn
{
    meta:
        description = "Indicators from Bulwark Black report: ShinyHunters Claims Massive Ivy League Breach: 2.2 Million Records from Harvard and UPenn"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/shinyhunters-claims-massive-ivy-league-breach-2-2-million-records-from-harvard-and-upenn/"
        date = "2026-02-04"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "claude.ai" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_ai_powered_attack_achieves_aws_admin_access_in_under_10_minutes_a_new_era_of_automated_intrusion
{
    meta:
        description = "Indicators from Bulwark Black report: AI-Powered Attack Achieves AWS Admin Access in Under 10 Minutes: A New Era of Automated Intrusions"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/ai-powered-attack-achieves-aws-admin-access-in-under-10-minutes-a-new-era-of-automated-intrusions/"
        date = "2026-02-04"
        net_indicators = 20
        file_hashes = 0
    strings:
        $n0 = "103.177.183.165" ascii wide
        $n1 = "104.155.129.177" ascii wide
        $n2 = "104.155.178.59" ascii wide
        $n3 = "104.197.169.222" ascii wide
        $n4 = "136.113.159.75" ascii wide
        $n5 = "152.58.47.83" ascii wide
        $n6 = "194.127.167.92" ascii wide
        $n7 = "197.51.170.131" ascii wide
        $n8 = "204.152.223.172" ascii wide
        $n9 = "34.171.37.34" ascii wide
        $n10 = "34.173.176.171" ascii wide
        $n11 = "34.30.49.235" ascii wide
        $n12 = "34.63.142.34" ascii wide
        $n13 = "34.66.36.38" ascii wide
        $n14 = "34.69.200.125" ascii wide
        $n15 = "34.9.139.206" ascii wide
        $n16 = "35.188.114.132" ascii wide
        $n17 = "35.192.38.204" ascii wide
        $n18 = "download.pytorch.org" ascii wide nocase
        $n19 = "terraform-bedrock-deploy.tf" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_shadowhs_fileless_linux_post_exploitation_framework_runs_entirely_in_memory
{
    meta:
        description = "Indicators from Bulwark Black report: ShadowHS: Fileless Linux Post-Exploitation Framework Runs Entirely in Memory"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/shadowhs-fileless-linux-post-exploitation-framework-runs-entirely-in-memory/"
        date = "2026-02-04"
        net_indicators = 11
        file_hashes = 26
    strings:
        $n0 = "204.93.253.180" ascii wide
        $n1 = "62.171.153.47" ascii wide
        $n2 = "91.92.242.200" ascii wide
        $n3 = "Kawpow.asia" ascii wide nocase
        $n4 = "Kawpow.asia.mine.zergpool.com" ascii wide nocase
        $n5 = "Kawpow.na" ascii wide nocase
        $n6 = "Kawpow.na.mine.zergpool.com" ascii wide nocase
        $n7 = "kawpow.eu" ascii wide nocase
        $n8 = "kawpow.eu.mine.zergpool.com" ascii wide nocase
        $n9 = "payload.so" ascii wide nocase
        $n10 = "zergpool.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "04a072481ebda2aa8f9e0dac371847f210199a503bf31950d796901d5dbe9d58" or
        hash.sha256(0, filesize) == "072e08b38a18a00d75b139a5bbb18ac4aa891f4fd013b55bfd3d6747e1ba0a27" or
        hash.sha256(0, filesize) == "0bb7d4d8a9c8f6b3622d07ae9892aa34dc2d0171209e2829d7d39d5024fd79ef" or
        hash.sha256(0, filesize) == "148f199591b9a696197ec72f8edb0cf4f90c5dcad0805cfab4a660f65bf27ef3" or
        hash.sha256(0, filesize) == "19df5436972b330910f7cb9856ef5fb17320f50b6ced68a76faecddcafa7dcd7" or
        hash.sha256(0, filesize) == "20c1819c2fb886375d9504b0e7e5debb87ec9d1a53073b1f3f36dd6a6ac3f427" or
        hash.sha256(0, filesize) == "3ba88f92a87c0bb01b13754190c36d8af7cd047f738ebb3d6f975960fe7614d6" or
        hash.sha256(0, filesize) == "3f014aa3e339d33760934f180915045daf922ca8ae07531c8e716608e683d92d" or
        hash.sha256(0, filesize) == "4069eaadc94efb5be43b768c47d526e4c080b7d35b4c9e7eeb63b8dcf0038d7d" or
        hash.sha256(0, filesize) == "574a17028b28fdf860e23754d16ede622e4e27bac11d33dbf5c39db501dfccdc" or
        hash.sha256(0, filesize) == "5a6b08d42cc8296b32034b132bab18d201a48c1628df3200e869722506dd4ec6" or
        hash.sha256(0, filesize) == "662d4e58e95b7b27eb961f3d81d299af961892c74bc7a1f2bb7a8f2442030d0e" or
        hash.sha256(0, filesize) == "666122c39b2fd4499678105420e21b938f0f62defdbc85275e14156ae69539d6" or
        hash.sha256(0, filesize) == "6c50fcf14af7f984a152016498bf4096dd1f71e9d35000301b8319bd50f7f6d0" or
        hash.sha256(0, filesize) == "72023e9829b0de93cf9f057858cac1bcd4a0499b018fb81406e08cd3053ae55b" or
        hash.sha256(0, filesize) == "7361c6861fdb08cab819b13bf2327bc82eebdd70651c7de1aed18515c1700d97" or
        hash.sha256(0, filesize) == "7fbab71fcc454401f6c3db91ed0afb0027266d5681c23900894f1002ceca389a" or
        hash.sha256(0, filesize) == "8007b94d367b7dbacaac4c1da0305b489f0f3f7a38770dcdb68d5824fe33d041" or
        hash.sha256(0, filesize) == "847846a0f0c76cf5699342a066378774f1101d2fb74850e3731dc9b74e12a69d" or
        hash.sha256(0, filesize) == "9f2cfc65b480695aa2fd847db901e6b1135b5ed982d9942c61b629243d6830dd" or
        hash.sha256(0, filesize) == "9fdaf64180b7d02b399d2a92f1cdd062af2e6584852ea597c50194b62cca3c0b" or
        hash.sha256(0, filesize) == "b3ee445675fce1fccf365a7b681b316124b1a5f0a7e87042136e91776b187f39" or
        hash.sha256(0, filesize) == "c679b408275f9624602702f5601954f3b51efbb1acc505950ee88175854e783f" or
        hash.sha256(0, filesize) == "e11bcba19ac628ae1d0b56e43646ae1b5da2ccc1da5162e6719d4b7d68d37096" or
        hash.sha256(0, filesize) == "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" or
        hash.sha256(0, filesize) == "e5a6deec56095d0ae702655ea2899c752f4a0735f9077605d933a04d45cd7e24"
}

rule BulwarkBlack_vibe_coding_gone_wrong_moltbook_ai_social_network_exposes_4_75_million_records_in_massive_databa
{
    meta:
        description = "Indicators from Bulwark Black report: Vibe Coding Gone Wrong: Moltbook AI Social Network Exposes 4.75 Million Records in Massive Database Breach"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/vibe-coding-gone-wrong-moltbook-ai-social-network-exposes-4-75-million-records-in-massive-database-breach/"
        date = "2026-02-03"
        net_indicators = 7
        file_hashes = 0
    strings:
        $n0 = "ehxbxtjliybbloantpwq.supabase.co" ascii wide nocase
        $n1 = "www.moltbook.com" ascii wide nocase
        $n2 = "https://ehxbxtjliybbloantpwq.supabase.co/rest/v1/agents?select" ascii wide nocase
        $n3 = "https://ehxbxtjliybbloantpwq.supabase.co/rest/v1/owners?select=email,x_handle,x_name&#x26;email=neq.null&#x26;limit=5" ascii wide nocase
        $n4 = "https://ehxbxtjliybbloantpwq.supabase.co/rest/v1/posts?id=eq.74b073fd-37db-4a32-a9e1-c7652e5c0d59" ascii wide nocase
        $n5 = "https://ehxbxtjliybbloantpwq.supabase.co/rest/v1/users" ascii wide nocase
        $n6 = "https://www.moltbook.com/_next/static/chunks/18e24eafc444b2b9.js" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_russian_legion_hacker_alliance_launches_opdenmark_campaign_against_danish_critical_infrastructur
{
    meta:
        description = "Indicators from Bulwark Black report: Russian Legion Hacker Alliance Launches OpDenmark Campaign Against Danish Critical Infrastructure"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/russian-legion-hacker-alliance-launches-opdenmark-campaign-against-danish-critical-infrastructure/"
        date = "2026-02-02"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "sundhed.dk" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_global_energy_systems_exposed_widespread_cybersecurity_gaps_found_in_power_grid_ot_networks
{
    meta:
        description = "Indicators from Bulwark Black report: Global Energy Systems Exposed: Widespread Cybersecurity Gaps Found in Power Grid OT Networks"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/global-energy-systems-exposed-widespread-cybersecurity-gaps-found-in-power-grid-ot-networks/"
        date = "2026-01-31"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "ThemesDNA.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_winrar_cve_2025_8088_russia_china_and_cybercriminals_unite_to_exploit_path_traversal_flaw
{
    meta:
        description = "Indicators from Bulwark Black report: WinRAR CVE-2025-8088: Russia, China, and Cybercriminals Unite to Exploit Path Traversal Flaw"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/winrar-cve-2025-8088-russia-china-and-cybercriminals-unite-to-exploit-path-traversal-flaw/"
        date = "2026-01-31"
        net_indicators = 0
        file_hashes = 44
    condition:
        hash.sha256(0, filesize) == "272c86c6db95f1ef8b83f672b65e64df16494cae261e1aba1aeb1e59dcb68524" or
        hash.sha256(0, filesize) == "29f89486bb820d40c9bee8bf70ee8664ea270b16e486af4a53ab703996943256" or
        hash.sha256(0, filesize) == "2c40e7cf613bf2806ff6e9bc396058fe4f85926493979189dbdbc7d615b7cb14" or
        hash.sha256(0, filesize) == "33580073680016f23bf474e6e62c61bf6a776e561385bfb06788a4713114ba9d" or
        hash.sha256(0, filesize) == "3b47df790abb4eb3ac570b50bf96bb1943d4b46851430ebf3fc36f645061491b" or
        hash.sha256(0, filesize) == "3b85d0261ab2531aba9e2992eb85273be0e26fe61e4592862d8f45d6807ceee4" or
        hash.sha256(0, filesize) == "498961237cf1c48f1e7764829818c5ba0af24a234c2f29c4420fb80276aec676" or
        hash.sha256(0, filesize) == "4f4567abe9ff520797b04b04255bbbe07ecdddb594559d436ac53314ec62c1b3" or
        hash.sha256(0, filesize) == "53f1b841d323c211c715b8f80d0efb9529440caae921a60340de027052946dd9" or
        hash.sha256(0, filesize) == "54305c7b95d8105601461bb18de87f1f679d833f15e38a9ee7895a0c8605c0d0" or
        hash.sha256(0, filesize) == "55b3dc57929d8eacfdadc71d92483eabe4874bf3d0189f861b145705a0f0a8fe" or
        hash.sha256(0, filesize) == "5b64786ed92545eeac013be9456e1ff03d95073910742e45ff6b88a86e91901b" or
        hash.sha256(0, filesize) == "5dee69127d501142413fb93fd2af8c8a378682c140c52b48990a5c41f2ce3616" or
        hash.sha256(0, filesize) == "68d9020aa9b509a6d018d6d9f4c77e7604a588b2848e05da6a4d9f82d725f91b" or
        hash.sha256(0, filesize) == "6d3586aa6603f1c1c79d7bd7e0b5c5f0cc8e8a84577c35d21b0f462656c2e1f9" or
        hash.sha256(0, filesize) == "867a05d67dd184d544d5513f4f07959a7c2b558197c99cb8139ea797ad9fbece" or
        hash.sha256(0, filesize) == "8a7ee2a8e6b3476319a3a0d5846805fd25fa388c7f2215668bc134202ea093fa" or
        hash.sha256(0, filesize) == "91e61fd77460393a89a8af657d09df6a815465f6ce22f1db8277d58342b32249" or
        hash.sha256(0, filesize) == "958921ea0995482fb04ea4a50bbdb654f272ab991046a43c1fdbd22da302d544" or
        hash.sha256(0, filesize) == "a54bcafd9d4ece87fa314d508a68f47b0ec3351c0a270aa2ed3a0e275b9db03c" or
        hash.sha256(0, filesize) == "a97f460bfa612f1d406823620d0d25e381f9b980a0497e2775269917a7150f04" or
        hash.sha256(0, filesize) == "ae93d9327a91e90bf7744c6ce0eb4affb3acb62a5d1b2dafd645cba9af28d795" or
        hash.sha256(0, filesize) == "aea13e5871b683a19a05015ff0369b412b985d47eb67a3af93f44400a026b4b0" or
        hash.sha256(0, filesize) == "b2b62703a1ef7d9d3376c6b3609cd901cbccdcca80fba940ce8ed3f4e54cdbe6" or
        hash.sha256(0, filesize) == "b53069a380a9dd3dc1c758888d0e50dd43935f16df0f7124c77569375a9f44f5" or
        hash.sha256(0, filesize) == "b90ef1d21523eeffbca17181ccccf269bca3840786fcbf5c73218c6e1d6a51a9" or
        hash.sha256(0, filesize) == "ba86b6e0199b8907427364246f049efd67dc4eda0b5078f4bc7607253634cf24" or
        hash.sha256(0, filesize) == "bb4856a66bf7e0de18522e35798c0a8734179c1aab21ed2ad6821aaa99e1cb4c" or
        hash.sha256(0, filesize) == "c7726c166e1947fdbf808a50b75ca7400d56fa6fef2a76cefe314848db22c76c" or
        hash.sha256(0, filesize) == "cf35ce47b35f1405969f40633fcf35132ca3ccb3fdfded8cc270fc2223049b80" or
        hash.sha256(0, filesize) == "cf8ebfd98da3025dc09d0b3bbeef874d8f9c4d4ba4937719f0a9a3aa04c81beb" or
        hash.sha256(0, filesize) == "d418f878fa02729b38b5384bcb3216872a968f5d0c9c77609d8c5aacedb07546" or
        hash.sha256(0, filesize) == "d981a16b9da1615514a02f5ebb38416a009f5621c0b718214d5b105c9f552389" or
        hash.sha256(0, filesize) == "ddd67dda5d58c7480152c9f6e8043c3ea7de2e593beedf86b867b83f005bf0cc" or
        hash.sha256(0, filesize) == "defe25e400d4925d8a2bb4b1181044d06a8bf61688fd9c9ea59f1e0bb7bc21d8" or
        hash.sha256(0, filesize) == "e836873479ff558cfb885097e8783356aad1f2d30b69d825b3a71cb7a57cf930" or
        hash.sha256(0, filesize) == "ea0869fa9d5e23bdd16cddfefbbf9c67744598f379be306ff652f910db1ba162" or
        hash.sha256(0, filesize) == "ed5b920dad5dcd3f9e55828f82a27211a212839c8942531c288535b92df7f453" or
        hash.sha256(0, filesize) == "edc1f7528ca93ec432daca820f47e08d218b79cceca1ee764966f8f90d6a58bd" or
        hash.sha256(0, filesize) == "ef0e1bb2d389ab8b5f15d2f83cf978662e18e31dbe875f39db563e8a019af577" or
        hash.sha256(0, filesize) == "f3e5667d02f95c001c717dfc5a0e100d2b701be4ec35a3e6875dc276431a7497" or
        hash.sha256(0, filesize) == "f6761b5341a33188a7a1ca7a904d5866e07b8ddbde9adebdbce4306923cfc60a" or
        hash.sha256(0, filesize) == "fc2a6138786fae4e33dc343aea2b1a7cd6411187307ea2c82cd96b45f6d1f2a0" or
        hash.sha256(0, filesize) == "ffc6c3805bbaef2c4003763fd5fac0ebcccf99a1656f10cf7677f6c2a5d16dbd"
}

rule BulwarkBlack_cve_2026_24061_11_year_old_gnu_telnetd_vulnerability_grants_instant_root_access
{
    meta:
        description = "Indicators from Bulwark Black report: CVE-2026-24061: 11-Year-Old GNU Telnetd Vulnerability Grants Instant Root Access"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/cve-2026-24061-11-year-old-gnu-telnetd-vulnerability-grants-instant-root-access/"
        date = "2026-01-31"
        net_indicators = 9
        file_hashes = 2
    strings:
        $n0 = "codeberg.org" ascii wide nocase
        $n1 = "lists.gnu.org" ascii wide nocase
        $n2 = "www.cve.org" ascii wide nocase
        $n3 = "www.cvedetails.com" ascii wide nocase
        $n4 = "https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc" ascii wide nocase
        $n5 = "https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7b" ascii wide nocase
        $n6 = "https://lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.html" ascii wide nocase
        $n7 = "https://www.cve.org/CVERecord?id=CVE-2026-24061" ascii wide nocase
        $n8 = "https://www.cvedetails.com/cve/CVE-2026-24061/" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha1(0, filesize) == "ccba9f748aa8d50a38d7748e2e60362edd6a32cc" or
        hash.sha1(0, filesize) == "fd702c02497b2f398e739e3119bed0b23dd7aa7b"
}

rule BulwarkBlack_ivanti_patches_two_critical_epmm_zero_day_vulnerabilities_under_active_exploitation
{
    meta:
        description = "Indicators from Bulwark Black report: Ivanti Patches Two Critical EPMM Zero-Day Vulnerabilities Under Active Exploitation"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/ivanti-patches-two-critical-epmm-zero-day-vulnerabilities-under-active-exploitation/"
        date = "2026-01-31"
        net_indicators = 5
        file_hashes = 0
    strings:
        $n0 = "12.5.1.0" ascii wide
        $n1 = "12.6.1.0" ascii wide
        $n2 = "12.8.0.0" ascii wide
        $n3 = "help.ivanti.com" ascii wide nocase
        $n4 = "https://help.ivanti.com/mi/help/en_us/core/11.x/gsg/CoreGettingStarted/Configuring_LDAP_servers.htm" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_ivanti_epmm_zero_days_actively_exploited_pre_auth_rce_via_bash_arithmetic_expansion
{
    meta:
        description = "Indicators from Bulwark Black report: Ivanti EPMM Zero-Days Actively Exploited: Pre-Auth RCE via Bash Arithmetic Expansion"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/ivanti-epmm-zero-days-actively-exploited-pre-auth-rce-via-bash-arithmetic-expansion/"
        date = "2026-01-31"
        net_indicators = 4
        file_hashes = 1
    strings:
        $n0 = "12.7.0.0" ascii wide
        $n1 = "12.8.0.0" ascii wide
        $n2 = "forums.ivanti.com" ascii wide nocase
        $n3 = "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "123aabf796106cfb2ab40cbbd43ba5b44fd937f1a5856e0a95640ba6f9d71843"
}

rule BulwarkBlack_android_malware_campaign_abuses_hugging_face_ai_platform_to_distribute_rat
{
    meta:
        description = "Indicators from Bulwark Black report: Android Malware Campaign Abuses Hugging Face AI Platform to Distribute RAT"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/android-malware-campaign-abuses-hugging-face-ai-platform-to-distribute-rat/"
        date = "2026-01-30"
        net_indicators = 18
        file_hashes = 9
    strings:
        $n0 = "108.187.7.133" ascii wide
        $n1 = "143.204.11.112" ascii wide
        $n2 = "148.135.44.146" ascii wide
        $n3 = "154.198.48.57" ascii wide
        $n4 = "au-club.top" ascii wide nocase
        $n5 = "cdn-lfs-us-1.hf.co" ascii wide nocase
        $n6 = "huggingface.co" ascii wide nocase
        $n7 = "trustbastion.com" ascii wide nocase
        $n8 = "www.trustbastion.com" ascii wide nocase
        $n9 = "hf.co/r" ascii wide nocase
        $n10 = "hf.co/repos/a5/0c/a50cf45d8b119af0cc75679c8307b05e29f2bc85b6d0bd55999dd018639f1c72/19f1a6b9ad1a9654e7c78fa2d37a3ec10192b01b636c5fc1995b80bf6f7dcb36?response-content-disposition=attachment%3B+filename*%3DUTF-8%27%27b.apk%3B+filename%3D%22b.apk%22%3B&amp" ascii wide nocase
        $n11 = "huggingface.co/datasets/xcvqsccm/sfxyt851/resolve/main/b.apk?download=true" ascii wide nocase
        $n12 = "https://cdn-lfs-us-1.hf.co/r" ascii wide nocase
        $n13 = "https://cdn-lfs-us-1.hf.co/repos/a5/0c/a50cf45d8b119af0cc75679c8307b05e29f2bc85b6d0bd55999dd018639f1c72/19f1a6b9ad1a9654e7c78fa2d37a3ec10192b01b636c5fc1995b80bf6f7dcb36?response-content-disposition=attachment%3B+filename*%3DUTF-8%27%27b.apk%3B+filename%3D%22b.apk%22%3B&amp;response-content-type=application%2Fvnd.android.package-archive&amp;Expires=1764089304&amp;Policy=eyJTdGF0ZW1lbnQiOlt7IkNvbmRpdGlvbiI6eyJEYXRlTGVzc1RoYW4iOnsiQVdTOkVwb2NoVGltZSI6MTc2NDA4OTMwNH19LCJSZXNvdXJjZSI6Imh0dHBzOi8vY2RuLWxmcy11cy0xLmhmLmNvL3JlcG9zL2E1LzBjL2E1MGNmNDVkOGIxMTlhZjBjYzc1Njc5YzgzMDdiMDVlMjlmMmJjODViNmQwYmQ1NTk5OWRkMDE4NjM5ZjFjNzIvMTlmMWE2YjlhZDFhOTY1NGU3Yzc4ZmEyZDM3YTNlYzEwMTkyYjAxYjYzNmM1ZmMxOTk1YjgwYmY2ZjdkY2IzNj9yZXNwb25zZS1jb250ZW50LWRpc3Bvc2l0aW9uPSomcmVzcG9uc2UtY29udGVudC10eXBlPSoifV19&amp;Signature=Mqc2vLuG17L9PD9eOO96Tbl8S1P6Efgzc1c%7EvjGQqg7jE6NcLyKqkIn7Koq06ybpChfuNeUOUSIRvqUXUd%7EAUt1mvivbp8cZla5frbYSx6ce2-Enp7KmhKXafgpPH6Hr8sGEt8EO56g3oF867bsCO3qH4Q9HqcX6DZZfgyysDxK22VIzEOYCoGqzIa0pj1gFr57PGdcyQJxqFDvpQ9KiCoLxqGjf4O5EpO-4bLJ53D3nZUTrDZX3sCHo7hUOxwqBMUefhgL0BKhL4JPfaBsHyfM9Cj%7EO1yPsf6CqZd%7EVfQWh9CH6ZW834YlKppFxovUMdg3dUHxUNUBDZg2-Nf3plw__&amp;Key-Pair-Id=K24J24Z295AEI9" ascii wide nocase
        $n14 = "https://huggingface.co" ascii wide nocase
        $n15 = "https://huggingface.co/datasets/xcvqsccm/sfxyt851/resolve/main/b.apk?download=true" ascii wide nocase
        $n16 = "https://www.trustbastion.com/xiazz.html" ascii wide nocase
        $n17 = "trustbastion.com/xiazz.html" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "15bdc66aca9fb7290165d460e6a993a9" or
        hash.md5(0, filesize) == "b62c906078644edd3439e2d986abd2e2" or
        hash.md5(0, filesize) == "b716a8a742fec3084b0f497abbfecfc0" or
        hash.md5(0, filesize) == "d184d705189e42b54c6243a55d6c9502" or
        hash.md5(0, filesize) == "d8b0fd515d860be2969cf441ea3b620d" or
        hash.md5(0, filesize) == "fc874c42ea76dd5f867649cbdf81e39b" or
        hash.sha1(0, filesize) == "bdf3779ddc10f241603be57a90865b680cde8c31" or
        hash.sha256(0, filesize) == "19f1a6b9ad1a9654e7c78fa2d37a3ec10192b01b636c5fc1995b80bf6f7dcb36" or
        hash.sha256(0, filesize) == "a50cf45d8b119af0cc75679c8307b05e29f2bc85b6d0bd55999dd018639f1c72"
}

rule BulwarkBlack_smartermail_fixes_critical_unauthenticated_rce_flaw_with_cvss_9_3_score
{
    meta:
        description = "Indicators from Bulwark Black report: SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/smartermail-fixes-critical-unauthenticated-rce-flaw-with-cvss-9-3-score/"
        date = "2026-01-30"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "CVE.org" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_match_group_data_breach_exposes_user_information_from_tinder_hinge_and_okcupid
{
    meta:
        description = "Indicators from Bulwark Black report: Match Group Data Breach Exposes User Information from Tinder, Hinge, and OkCupid"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/match-group-data-breach-exposes-user-information-from-tinder-hinge-and-okcupid/"
        date = "2026-01-30"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "Match.com" ascii wide nocase
        $n1 = "matchinternal.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_solarwinds_fixes_six_critical_web_help_desk_vulnerabilities_including_rce_and_auth_bypass
{
    meta:
        description = "Indicators from Bulwark Black report: SolarWinds Fixes Six Critical Web Help Desk Vulnerabilities Including RCE and Auth Bypass"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/solarwinds-fixes-six-critical-web-help-desk-vulnerabilities-including-rce-and-auth-bypass/"
        date = "2026-01-29"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "horizon3.ai" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_google_disrupts_worlds_largest_residential_proxy_botnet
{
    meta:
        description = "Indicators from Bulwark Black report: Google Disrupts World’s Largest Residential Proxy Botnet"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/google-disrupts-worlds-largest-residential-proxy-botnet/"
        date = "2026-01-29"
        net_indicators = 27
        file_hashes = 16
    strings:
        $n0 = "1.3.6.1" ascii wide
        $n1 = "45.78.214.188" ascii wide
        $n2 = "49.51.68.143" ascii wide
        $n3 = "60.2.1.3" ascii wide
        $n4 = "00857cca77b615c369f48ead5f8eb7f3.com" ascii wide nocase
        $n5 = "0aa0cf0637d66c0d.com" ascii wide nocase
        $n6 = "31d58c226fc5a0aa976e13ca9ecebcc8.com" ascii wide nocase
        $n7 = "3k7m1n9p4q2r6s8t0v5w2x4y6z8u9.com" ascii wide nocase
        $n8 = "442fe7151fb1e9b5.com" ascii wide nocase
        $n9 = "6b86b273ff34fce1.online" ascii wide nocase
        $n10 = "7x2k9n4p1q0r5s8t3v6w0y2z4u7b9.com" ascii wide nocase
        $n11 = "8b21a945159f23b740c836eb50953818.com" ascii wide nocase
        $n12 = "8f00b204e9800998.com" ascii wide nocase
        $n13 = "a7b37115ce3cc2eb.com" ascii wide nocase
        $n14 = "a8d3b9e1f5c7024d6e0b7a2c9f1d83e5.com" ascii wide nocase
        $n15 = "aa86a52a98162b7d.com" ascii wide nocase
        $n16 = "af4760df2c08896a9638e26e7dd20aae.com" ascii wide nocase
        $n17 = "b5e9a2d7f4c8e3b1a0d6f2e9c5b8a7d.com" ascii wide nocase
        $n18 = "bdrv7wlbszfotkqf.uk" ascii wide nocase
        $n19 = "cfe47df26c8eaf0a7c136b50c703e173.com" ascii wide nocase
        $n20 = "e4f8c1b9a2d7e3f6c0b5a8d9e2f1c4d.com" ascii wide nocase
        $n21 = "hexsdk.com" ascii wide nocase
        $n22 = "packetsdk.io" ascii wide nocase
        $n23 = "packetsdk.net" ascii wide nocase
        $n24 = "packetsdk.xyz" ascii wide nocase
        $n25 = "v46wd6uramzkmeeo.in" ascii wide nocase
        $n26 = "willmam.com" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "00857cca77b615c369f48ead5f8eb7f3" or
        hash.md5(0, filesize) == "0c855f87a7574b28df383eca5084fcdc" or
        hash.md5(0, filesize) == "31d58c226fc5a0aa976e13ca9ecebcc8" or
        hash.md5(0, filesize) == "8a9bd7e7a806b2cc606b7a1d8f495662" or
        hash.md5(0, filesize) == "8b21a945159f23b740c836eb50953818" or
        hash.md5(0, filesize) == "993ae4fe78b879239bdc14dfbc0963cd" or
        hash.md5(0, filesize) == "a8d3b9e1f5c7024d6e0b7a2c9f1d83e5" or
        hash.md5(0, filesize) == "af4760df2c08896a9638e26e7dd20aae" or
        hash.md5(0, filesize) == "c8eb024c053f82831f2738bd48afc256" or
        hash.md5(0, filesize) == "cfe47df26c8eaf0a7c136b50c703e173" or
        hash.sha256(0, filesize) == "01ac6012d4316b68bb3165ee451f2fcc494e4e37011a73b8cf2680de3364fcf4" or
        hash.sha256(0, filesize) == "2d1891b6d0c158ad7280f0f30f3c9d913960a793c6abcda249f9c76e13014e45" or
        hash.sha256(0, filesize) == "59cbdecfc01eba859d12fbeb48f96fe3fe841ac1aafa6bd38eff92f0dcfd4554" or
        hash.sha256(0, filesize) == "aef34f14456358db91840c416e55acc7d10185ff2beb362ea24697d7cdad321f" or
        hash.sha256(0, filesize) == "b0726bdd53083968870d0b147b72dad422d6d04f27cd52a7891d038ee83aef5b" or
        hash.sha256(0, filesize) == "ba9b1f4cc2c7f4aeda7a1280bbc901671f4ec3edaa17f1db676e17651e9bff5f"
}

rule BulwarkBlack_soundcloud_data_breach_exposes_29_8_million_user_accounts
{
    meta:
        description = "Indicators from Bulwark Black report: SoundCloud Data Breach Exposes 29.8 Million User Accounts"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/soundcloud-data-breach-exposes-29-8-million-user-accounts/"
        date = "2026-01-28"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "HaveIBeenPwned.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_fortinet_blocks_actively_exploited_forticloud_sso_zero_day_until_patch_is_ready
{
    meta:
        description = "Indicators from Bulwark Black report: Fortinet Blocks Actively Exploited FortiCloud SSO Zero-Day Until Patch is Ready"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/fortinet-blocks-actively-exploited-forticloud-sso-zero-day-until-patch-is-ready/"
        date = "2026-01-28"
        net_indicators = 10
        file_hashes = 0
    strings:
        $n0 = "104.28.195.105" ascii wide
        $n1 = "104.28.195.106" ascii wide
        $n2 = "104.28.212.114" ascii wide
        $n3 = "104.28.212.115" ascii wide
        $n4 = "104.28.227.105" ascii wide
        $n5 = "104.28.227.106" ascii wide
        $n6 = "104.28.244.114" ascii wide
        $n7 = "104.28.244.115" ascii wide
        $n8 = "217.119.139.50" ascii wide
        $n9 = "37.1.209.19" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_fake_clawdbot_vs_code_extension_deploys_screenconnect_rat
{
    meta:
        description = "Indicators from Bulwark Black report: Fake Clawdbot VS Code Extension Deploys ScreenConnect RAT"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/fake-clawdbot-vs-code-extension-deploys-screenconnect-rat/"
        date = "2026-01-27"
        net_indicators = 18
        file_hashes = 4
    strings:
        $n0 = "178.16.54.253" ascii wide
        $n1 = "179.43.176.32" ascii wide
        $n2 = "clawdbot.getintwopc.site" ascii wide nocase
        $n3 = "darkgptprivate.com" ascii wide nocase
        $n4 = "getintwopc.site" ascii wide nocase
        $n5 = "meeting.bulletmailer.net" ascii wide nocase
        $n6 = "www.aikido.dev" ascii wide nocase
        $n7 = "www.dropbox.com" ascii wide nocase
        $n8 = "bulletmailer.net" ascii wide nocase
        $n9 = "dropbox.com/scl/fi/tmwi4j86op04r9qo2xdgh/zoomupdate.msi?rlkey=ymr9yn5p3q2w2l3uz9cg71dvm&amp" ascii wide nocase
        $n10 = "getintwopc.site/config.json" ascii wide nocase
        $n11 = "getintwopc.site/config.json&#x27" ascii wide nocase
        $n12 = "http://clawdbot.getintwopc.site/config.json&#x27" ascii wide nocase
        $n13 = "http://clawdbot.getintwopc.site/dl/Lightshot.dll&#x27" ascii wide nocase
        $n14 = "http://clawdbot.getintwopc.site/dl/Lightshot.exe&#x27" ascii wide nocase
        $n15 = "https://darkgptprivate.com/d111&quot" ascii wide nocase
        $n16 = "https://www.aikido.dev/blog/fake-clawdbot-vscode-extension-malware" ascii wide nocase
        $n17 = "https://www.dropbox.com/scl/fi/tmwi4j86op04r9qo2xdgh/zoomupdate.msi?rlkey=ymr9yn5p3q2w2l3uz9cg71dvm&amp;st=q93av9p6&amp;dl=1" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "04ef48b104d6ebd05ad70f6685ade26c1905495456f52dfe0fb42f550bd43388" or
        hash.sha256(0, filesize) == "adbcdb613c04fd51936cb0863d2417604db0cd04792ab7cae02526d48944c77b" or
        hash.sha256(0, filesize) == "d1e0c26774cb8beabaf64f119652719f673fb530368d5b2166178191ad5fcbea" or
        hash.sha256(0, filesize) == "e20b920c7af988aa215c95bbaa365d005dd673544ab7e3577b60fecf11dcdea2"
}

rule BulwarkBlack_chinese_apt_groups_leverage_peckbirdy_javascript_c2_framework_since_2023
{
    meta:
        description = "Indicators from Bulwark Black report: Chinese APT Groups Leverage PeckBirdy JavaScript C2 Framework Since 2023"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/chinese-apt-groups-leverage-peckbirdy-javascript-c2-framework-since-2023/"
        date = "2026-01-27"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "47.238.184.9" ascii wide
    condition:
        any of ($n*)
}

rule BulwarkBlack_complete_guide_setting_up_freepbx_with_vps_docker_and_vpn_cgnat_bypass_solution
{
    meta:
        description = "Indicators from Bulwark Black report: Complete Guide: Setting Up FreePBX with VPS, Docker, and VPN (CGNAT Bypass Solution)"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/complete-guide-setting-up-freepbx-with-vps-docker-and-vpn-cgnat-bypass-solution/"
        date = "2025-07-18"
        net_indicators = 3
        file_hashes = 0
    strings:
        $n0 = "mypbx.pstn.ashburn.twilio.com" ascii wide nocase
        $n1 = "twilio.com" ascii wide nocase
        $n2 = "yourname.pstn.ashburn.twilio.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_how_to_communicate_a_cyber_breach_to_minimize_reputational_damage
{
    meta:
        description = "Indicators from Bulwark Black report: How to communicate a cyber breach to minimize reputational damage"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/how-to-communicate-a-cyber-breach-to-minimize-reputational-damage/"
        date = "2024-03-22"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "www.ambitiouspr.co.uk" ascii wide nocase
        $n1 = "https://www.ambitiouspr.co.uk/" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_new_go_loader_pushes_rhadamanthys_stealer
{
    meta:
        description = "Indicators from Bulwark Black report: New Go loader pushes Rhadamanthys stealer"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/new-go-loader-pushes-rhadamanthys-stealer/"
        date = "2024-03-22"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "arnaudpairoto.com" ascii wide nocase
        $n1 = "putty.org" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_the_updated_apt_playbook_tales_from_the_kimsuky_threat_actor_group
{
    meta:
        description = "Indicators from Bulwark Black report: The Updated APT Playbook: Tales from the Kimsuky threat actor group"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/the-updated-apt-playbook-tales-from-the-kimsuky-threat-actor-group/"
        date = "2024-03-22"
        net_indicators = 7
        file_hashes = 9
    strings:
        $n0 = "00701111.000webhostapp.com" ascii wide nocase
        $n1 = "gosiweb.gosiclass.com" ascii wide nocase
        $n2 = "niscarea.com" ascii wide nocase
        $n3 = "gosiclass.com/m/gnu/convert/html/com/list.php?query=6" ascii wide nocase
        $n4 = "http://gosiweb.gosiclass.com/m/gnu/convert/html/com/list.php?query=6" ascii wide nocase
        $n5 = "https://niscarea.com/in.php?cn=[base64]&amp;fn=[DateTime" ascii wide nocase
        $n6 = "niscarea.com/in.php?cn=[base64" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "364d4fdf430477222fe854b3cd5b6d40" or
        hash.md5(0, filesize) == "71db2ae9c36403cec1fd38864d64f239" or
        hash.md5(0, filesize) == "f35b05779e9538cec363ca37ab38e287" or
        hash.sha1(0, filesize) == "5c7b2705155023e6e438399d895d30bf924e0547" or
        hash.sha1(0, filesize) == "b5224224fdbabdea53a91a96e9f816c6f9a8708c" or
        hash.sha1(0, filesize) == "d4fa57f9c9e35222a8cacddc79055c1d76907fb9" or
        hash.sha256(0, filesize) == "c62677543eeb50e0def44fc75009a7748cdbedd0a3ccf62f50d7f219f6a5aa05" or
        hash.sha256(0, filesize) == "da79eea1198a1a10e2ffd50fd949521632d8f252fb1aadb57a45218482b9fd89" or
        hash.sha256(0, filesize) == "e8000ddfddbe120b5f2fb3677abbad901615d1abd01a0de204fade5d2dd5ad0d"
}

rule BulwarkBlack_endpoints_vs_routes_what_every_api_hacker_needs_to_know
{
    meta:
        description = "Indicators from Bulwark Black report: Endpoints vs Routes: What every API hacker needs to know"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/endpoints-vs-routes-what-every-api-hacker-needs-to-know/"
        date = "2024-02-14"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "u.id" ascii wide nocase
        $n1 = "user.id" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_announcing_cvemap_from_projectdiscovery
{
    meta:
        description = "Indicators from Bulwark Black report: Announcing cvemap from ProjectDiscovery"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/announcing-cvemap-from-projectdiscovery/"
        date = "2024-01-26"
        net_indicators = 3
        file_hashes = 0
    strings:
        $n0 = "cloud.projectdiscovery.io" ascii wide nocase
        $n1 = "https://cloud.projectdiscovery.io/" ascii wide nocase
        $n2 = "https://cloud.projectdiscovery.io/?ref=api_key" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_how_to_protect_evilginx_using_cloudflare_and_html_obfuscation
{
    meta:
        description = "Indicators from Bulwark Black report: How to protect Evilginx using Cloudflare and HTML Obfuscation"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/how-to-protect-evilginx-using-cloudflare-and-html-obfuscation/"
        date = "2024-01-26"
        net_indicators = 7
        file_hashes = 0
    strings:
        $n0 = "academy.breakdev.org" ascii wide nocase
        $n1 = "help.evilginx.com" ascii wide nocase
        $n2 = "index.ht" ascii wide nocase
        $n3 = "www.r-tec.net" ascii wide nocase
        $n4 = "https://academy.breakdev.org/evilginx-mastery" ascii wide nocase
        $n5 = "https://help.evilginx.com/docs/category/getting-started" ascii wide nocase
        $n6 = "https://www.r-tec.net/r-tec-blog-evade-signature-based-phishing-detections.html" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_the_bug_hunters_methodology_live
{
    meta:
        description = "Indicators from Bulwark Black report: THE BUG HUNTERS METHODOLOGY LIVE"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/the-bug-hunters-methodology-live/"
        date = "2024-01-12"
        net_indicators = 3
        file_hashes = 0
    strings:
        $n0 = "Hunter.io" ascii wide nocase
        $n1 = "tbhmlive.com" ascii wide nocase
        $n2 = "https://tbhmlive.com/" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_faking_bluetooth_le_with_an_nrf24l01_module
{
    meta:
        description = "Indicators from Bulwark Black report: FAKING BLUETOOTH LE WITH AN NRF24L01+ MODULE"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/faking-bluetooth-le-with-an-nrf24l01-module/"
        date = "2024-01-11"
        net_indicators = 4
        file_hashes = 0
    strings:
        $n0 = "hackaday.io" ascii wide nocase
        $n1 = "www.sparkfun.com" ascii wide nocase
        $n2 = "https://hackaday.io/project/162131-graphical-pinout-generator/" ascii wide nocase
        $n3 = "https://www.sparkfun.com/news/1947" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_dreambus_unleashes_metabase_mayhem_with_new_exploit_module
{
    meta:
        description = "Indicators from Bulwark Black report: DreamBus Unleashes Metabase Mayhem With New Exploit Module"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/dreambus-unleashes-metabase-mayhem-with-new-exploit-module/"
        date = "2024-01-11"
        net_indicators = 20
        file_hashes = 2
    strings:
        $n0 = "139.59.150.7" ascii wide
        $n1 = "1.46.6.1" ascii wide
        $n2 = "92.204.243.155" ascii wide
        $n3 = "HyMbvhNq.tor2web.in" ascii wide nocase
        $n4 = "HyMbvhNq.tor2web.it" ascii wide nocase
        $n5 = "HyMbvhNq.tor2web.re" ascii wide nocase
        $n6 = "PcSKnocJ.tor2web.in" ascii wide nocase
        $n7 = "PcSKnocJ.tor2web.it" ascii wide nocase
        $n8 = "PcSKnocJ.tor2web.re" ascii wide nocase
        $n9 = "dns.twnic.tw" ascii wide nocase
        $n10 = "doh-ch.blahdns.com" ascii wide nocase
        $n11 = "doh-de.blahdns.com" ascii wide nocase
        $n12 = "doh-jp.blahdns.com" ascii wide nocase
        $n13 = "doh-sg.blahdns.com" ascii wide nocase
        $n14 = "doh.dns.sb" ascii wide nocase
        $n15 = "doh.li" ascii wide nocase
        $n16 = "ident.me" ascii wide nocase
        $n17 = "ip.sb" ascii wide nocase
        $n18 = "p2pool.it" ascii wide nocase
        $n19 = "relay.tor2socks.in" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "ae776206422e886961eefb358c4fefda" or
        hash.md5(0, filesize) == "de2381ccba8aa44b77bda1c971a33b5e"
}

rule BulwarkBlack_backdoor_win32_carbanak_anunak_named_pipe_null_dacl
{
    meta:
        description = "Indicators from Bulwark Black report: Backdoor.Win32 Carbanak (Anunak) / Named Pipe Null DACL"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/backdoor-win32-carbanak-anunak-named-pipe-null-dacl/"
        date = "2024-01-11"
        net_indicators = 2
        file_hashes = 1
    strings:
        $n0 = "malvuln.com" ascii wide nocase
        $n1 = "https://malvuln.com/advisory/b8e1e5b832e5947f41fd6ae6ef6d09a1.txt" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "b8e1e5b832e5947f41fd6ae6ef6d09a1"
}

rule BulwarkBlack_financially_motivated_threat_actors_misusing_app_installer
{
    meta:
        description = "Indicators from Bulwark Black report: Financially motivated threat actors misusing App Installer"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/financially-motivated-threat-actors-misusing-app-installer/"
        date = "2024-01-09"
        net_indicators = 47
        file_hashes = 9
    strings:
        $n0 = "1204knos.ru" ascii wide nocase
        $n1 = "1204networks.ru" ascii wide nocase
        $n2 = "abobe.ithr.org" ascii wide nocase
        $n3 = "aka.ms" ascii wide nocase
        $n4 = "amgreetings.tech" ascii wide nocase
        $n5 = "amgreetings.tech-department.us" ascii wide nocase
        $n6 = "amydeks.ithr.org" ascii wide nocase
        $n7 = "api.store" ascii wide nocase
        $n8 = "cabotcorpsupport-my.sharepoint.com" ascii wide nocase
        $n9 = "cbre.tech" ascii wide nocase
        $n10 = "cbre.tech-department.us" ascii wide nocase
        $n11 = "formeld.tech" ascii wide nocase
        $n12 = "formeld.tech-department.us" ascii wide nocase
        $n13 = "gertefin.com" ascii wide nocase
        $n14 = "hubergroup.tech" ascii wide nocase
        $n15 = "hubergroup.tech-department.us" ascii wide nocase
        $n16 = "info-zoomapp.com" ascii wide nocase
        $n17 = "kellyhrservices-my.sharepoint.com" ascii wide nocase
        $n18 = "kellyservices-hr.com" ascii wide nocase
        $n19 = "kellyservicesheadhunter-my.sharepoint.com" ascii wide nocase
        $n20 = "kellyserviceshr-my.sharepoint.com" ascii wide nocase
        $n21 = "kellyservicesrecruitmentdep-my.sharepoint.com" ascii wide nocase
        $n22 = "mckinseyhrcompany-my.sharepoint.com" ascii wide nocase
        $n23 = "meetlng.group" ascii wide nocase
        $n24 = "nixonpeabody.tech" ascii wide nocase
        $n25 = "nixonpeabody.tech-department.us" ascii wide nocase
        $n26 = "perimeter81support-my.sharepoint.com" ascii wide nocase
        $n27 = "scheta.site" ascii wide nocase
        $n28 = "septcntr.com" ascii wide nocase
        $n29 = "sharepoint.com" ascii wide nocase
        $n30 = "storageplace.pro" ascii wide nocase
        $n31 = "sun1.space" ascii wide nocase
        $n32 = "tab1eu.ithr.org" ascii wide nocase
        $n33 = "teannviewer.ithr.org" ascii wide nocase
        $n34 = "tech-department.us" ascii wide nocase
        $n35 = "thecyberwire.com" ascii wide nocase
        $n36 = "tnetworkslicense.ru" ascii wide nocase
        $n37 = "webmicrosoftservicesystem.com" ascii wide nocase
        $n38 = "zoonn.ithr.org" ascii wide nocase
        $n39 = "zoonn.meetlng.group" ascii wide nocase
        $n40 = "https://aka.ms/threatintelblog" ascii wide nocase
        $n41 = "https://scheta.site/api.store/Setup.msix" ascii wide nocase
        $n42 = "https://scheta.site/api.store/ZoomInstaller.msix" ascii wide nocase
        $n43 = "https://thecyberwire.com/podcasts/microsoft-threat-intelligence" ascii wide nocase
        $n44 = "ithr.org" ascii wide nocase
        $n45 = "scheta.site/api.store/Setup.msix" ascii wide nocase
        $n46 = "scheta.site/api.store/ZoomInstaller.msix" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "06b4aebbc3cd62e0aadd1852102645f9a00cc7eea492c0939675efba7566a6de" or
        hash.sha256(0, filesize) == "11b71429869f29122236a44a292fde3f0269cde8eb76a52c89139f79f4b97e63" or
        hash.sha256(0, filesize) == "2ba527fb8e31cb209df8d1890a63cda9cd4433aa0b841ed8b86fa801aff4ccbd" or
        hash.sha256(0, filesize) == "2ed5660c7b768b4c2a7899d00773af60cd4396f24a2f7d643ccc1bf74a403970" or
        hash.sha256(0, filesize) == "44cac5bf0bab56b0840bd1c7b95f9c7f5078ff417705eeaaf5ea5a2167a81dd5" or
        hash.sha256(0, filesize) == "48aa2393ef590bab4ff2fd1e7d95af36e5b6911348d7674347626c9aaafa255e" or
        hash.sha256(0, filesize) == "7e646dfe7b7f330cb21db07b94f611eb39f604fab36e347fb884f797ba462402" or
        hash.sha256(0, filesize) == "b79633917e51da2a4401473d08719f493d61fd64a1b10fe482c12d984d791ccb" or
        hash.sha256(0, filesize) == "ffb45dc14ea908b21e01e87ec18725dff560c093884005c2b71277e2de354866"
}

rule BulwarkBlack_the_underground_economist_volume_4_issue_1
{
    meta:
        description = "Indicators from Bulwark Black report: The Underground Economist: Volume 4, Issue 1"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/the-underground-economist-volume-4-issue-1/"
        date = "2024-01-09"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "exploit.in" ascii wide nocase
        $n1 = "Marinetraffic.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_custom_gpts_a_case_of_malware_analysis_and_ioc_analyzing
{
    meta:
        description = "Indicators from Bulwark Black report: Custom GPTs: A Case of Malware Analysis and IoC Analyzing"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/custom-gpts-a-case-of-malware-analysis-and-ioc-analyzing/"
        date = "2024-01-09"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "seo.ai" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_deceptive_cracked_software_spreads_lumma_variant_on_youtube
{
    meta:
        description = "Indicators from Bulwark Black report: Deceptive Cracked Software Spreads Lumma Variant on YouTube"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/deceptive-cracked-software-spreads-lumma-variant-on-youtube/"
        date = "2024-01-08"
        net_indicators = 13
        file_hashes = 4
    strings:
        $n0 = "119.0.0.0" ascii wide
        $n1 = "176.113.115.224" ascii wide
        $n2 = "176.113.115.226" ascii wide
        $n3 = "176.113.115.227" ascii wide
        $n4 = "176.113.115.229" ascii wide
        $n5 = "176.113.115.232" ascii wide
        $n6 = "Netovrema.pw" ascii wide nocase
        $n7 = "chincenterblandwka.pw" ascii wide nocase
        $n8 = "cutt.ly" ascii wide nocase
        $n9 = "opposesicknessopw.pw" ascii wide nocase
        $n10 = "politefrightenpowoa.pw" ascii wide nocase
        $n11 = "cutt.ly/lwD7B7lp" ascii wide nocase
        $n12 = "http://cutt.ly/lwD7B7lp,”" ascii wide nocase
    condition:
        any of ($n*) or
        hash.sha256(0, filesize) == "01a23f8f59455eb97f55086c21be934e6e5db07e64acb6e63c8d358b763dab4f" or
        hash.sha256(0, filesize) == "483672a00ea676236ea423c91d576542dc572be864a4162df031faf35897a532" or
        hash.sha256(0, filesize) == "48cbeb1b1ca0a7b3a9f6ac56273fbaf85e78c534e26fb2bca1152ecd7542af54" or
        hash.sha256(0, filesize) == "7603c6dd9edca615d6dc3599970c203555b57e2cab208d87545188b57aa2c6b1"
}

rule BulwarkBlack_javascript_malware_50000_bank_users_at_risk_worldwide
{
    meta:
        description = "Indicators from Bulwark Black report: JavaScript Malware: 50,000+ Bank Users at Risk Worldwide"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/javascript-malware-50000-bank-users-at-risk-worldwide/"
        date = "2024-01-07"
        net_indicators = 1
        file_hashes = 0
    strings:
        $n0 = "jscdnpack.com" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_prior_to_cyber_attack_russian_attackers_spent_months_inside_the_ukraine_telecoms_giant
{
    meta:
        description = "Indicators from Bulwark Black report: Prior to Cyber Attack, Russian Attackers Spent Months Inside the Ukraine Telecoms Giant"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/prior-to-cyber-attack-russian-attackers-spent-months-inside-the-ukraine-telecoms-giant/"
        date = "2024-01-07"
        net_indicators = 7
        file_hashes = 0
    strings:
        $n0 = "Booking.com" ascii wide nocase
        $n1 = "BugsBounty.com" ascii wide nocase
        $n2 = "Builder.ai" ascii wide nocase
        $n3 = "Coinopsy.com" ascii wide nocase
        $n4 = "Collectibles.com" ascii wide nocase
        $n5 = "Discord.io" ascii wide nocase
        $n6 = "Duck.ai" ascii wide nocase
    condition:
        any of ($n*)
}

rule BulwarkBlack_tackling_anti_analysis_techniques_of_guloader_and_redline_stealer
{
    meta:
        description = "Indicators from Bulwark Black report: Tackling Anti-Analysis Techniques of GuLoader and RedLine Stealer"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/tackling-anti-analysis-techniques-of-guloader-and-redline-stealer/"
        date = "2024-01-05"
        net_indicators = 0
        file_hashes = 2
    condition:
        hash.sha256(0, filesize) == "32ea41ff050f09d0b92967588a131e0a170cb46baf7ee58d03277d09336f89d9" or
        hash.sha256(0, filesize) == "a4cf69f849e9ea0ab4eba1cdc1ef2a973591bc7bb55901fdbceb412fb1147ef9"
}

rule BulwarkBlack_100_days_of_yara_2023
{
    meta:
        description = "Indicators from Bulwark Black report: 100 Days of YARA – 2023"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/100-days-of-yara-2023/"
        date = "2024-01-05"
        net_indicators = 16
        file_hashes = 20
    strings:
        $n0 = "ci.appveyor.com" ascii wide nocase
        $n1 = "community.spiceworks.com" ascii wide nocase
        $n2 = "export.name" ascii wide nocase
        $n3 = "interoperability.blob.core.windows.net" ascii wide nocase
        $n4 = "osandamalith.com" ascii wide nocase
        $n5 = "redmaple.tech" ascii wide nocase
        $n6 = "section.name" ascii wide nocase
        $n7 = "www.garykessler.net" ascii wide nocase
        $n8 = "www.tarlogic.com" ascii wide nocase
        $n9 = "https://ci.appveyor.com/project/plusvic/yara/build/job/wthlb30bklmlns0a/artifacts" ascii wide nocase
        $n10 = "https://community.spiceworks.com/topic/2107142-what-are-all-of-the-file-types-on-a-windows-pc-that-contain-executable-code" ascii wide nocase
        $n11 = "https://interoperability.blob.core.windows.net/files/MS-ONE/%5bMS-ONE%5d.pdf" ascii wide nocase
        $n12 = "https://osandamalith.com/2020/07/19/exploring-the-ms-dos-stub/" ascii wide nocase
        $n13 = "https://redmaple.tech/blogs/macho-files/" ascii wide nocase
        $n14 = "https://www.garykessler.net/library/file_sigs.html" ascii wide nocase
        $n15 = "https://www.tarlogic.com/blog/seloaddriverprivilege-privilege-escalation/" ascii wide nocase
    condition:
        any of ($n*) or
        hash.md5(0, filesize) == "269af2751efee65b1ab00622816c83e6" or
        hash.md5(0, filesize) == "30851d4a2b31e9699084a06e765e21b0" or
        hash.md5(0, filesize) == "4f6b9c644d4fe517889b3fbb0b4271ca" or
        hash.md5(0, filesize) == "72f60d7f4ce22db4506547ad555ea0b1" or
        hash.md5(0, filesize) == "c0de41e45352714500771d43f0d8c4c3" or
        hash.md5(0, filesize) == "f34d5f2d4577ed6d9ceec516c1f5a744" or
        hash.sha1(0, filesize) == "05ef26965be930fade49e5dcba73b9fefc04757e" or
        hash.sha1(0, filesize) == "2b631d0ee47650923955398921c1ceccc3e38cb1" or
        hash.sha256(0, filesize) == "003669761229d3e1db0f5a5b333ef62b3dffcc8e27c821ce9018362e0a2df7e9" or
        hash.sha256(0, filesize) == "1db32411a88725b259a7f079bdebd5602f11130f71ec35bec9d18134adbd4352" or
        hash.sha256(0, filesize) == "2218904238dc4f8bb5bb838ed4fa779f7873814d7711a28ba59603826ae020aa" or
        hash.sha256(0, filesize) == "5904bc90aec64b12caa5d352199bd4ec2f5a3a9ac0a08adf954689a58eff3f2a" or
        hash.sha256(0, filesize) == "76d54a57bf9521f6558b588acd0326249248f91b27ebc25fd94ebe92dc497809" or
        hash.sha256(0, filesize) == "a37a290863fe29b9812e819e4c5b047c44e7a7d7c40e33da6f5662e1957862ab" or
        hash.sha256(0, filesize) == "a44b35f376f6e493580c988cd697e8a2d64c82ab665dfd100115fb6f700bb82a" or
        hash.sha256(0, filesize) == "b7d217f13550227bb6d80d05bde26e43cd752a870973052080a72a510c444b5a" or
        hash.sha256(0, filesize) == "c98ac83685cb5f7f72e832998fec753910e77d1b8eee638acb508252912f6cf6" or
        hash.sha256(0, filesize) == "eb30a1822bd6f503f8151cb04bfd315a62fa67dbfe1f573e6fcfd74636ecedd5" or
        hash.sha256(0, filesize) == "ed48d56a47982c3c9b39ee8859e0b764454ab9ac6e7a7866cdef5c310521be19" or
        hash.sha256(0, filesize) == "f119cc4cb5a7972bdc80548982b2b63fac5b48d5fce1517270db67c858e9e8b0"
}

rule BulwarkBlack_hide_and_seek_in_windows_closet_unmasking_the_winsxs_hijacking_hideout
{
    meta:
        description = "Indicators from Bulwark Black report: Hide and Seek in Windows’ Closet: Unmasking the WinSxS Hijacking Hideout"
        author = "Bulwark Black LLC"
        reference = "https://bulwarkblack.com/hide-and-seek-in-windows-closet-unmasking-the-winsxs-hijacking-hideout/"
        date = "2024-01-05"
        net_indicators = 2
        file_hashes = 0
    strings:
        $n0 = "www.securityjoes.com" ascii wide nocase
        $n1 = "https://www.securityjoes.com/post/hide-and-seek-in-windows-closet-unmasking-the-winsxs-hijacking-hideout" ascii wide nocase
    condition:
        any of ($n*)
}
