MALWARE-OTHER --
MALWARE-OTHER Unix.Trojan.Wolfsbane download attempt
This rule is specifically looking for some unique bytecode contained in the Wolfsbane installation utility used by APTs.
This rule triggers on a file transfer of the Unix.Trojan.Wolfsbane malware.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Execution::User Execution::Malicious File
None
No information provided
None