MALWARE-OTHER --
MALWARE-OTHER Unix.Trojan.Helldown variant upload attempt
This rule specifically is looking for a known loader tool used by the Helldown ransomware group to install a backdoor on a targeted firewall.
This rule triggers on a known malicious file upload
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Execution::User Execution::Malicious File
None
No information provided
None