Detection rules › Equivalence class
eq_0006 — 2 rules with the same canonical form
Members
Stages and predicates (per member)
Each member's stage rendered in its own native syntax (verbatim source where the IR captures it; falls back to the synthesised native form for the few stage types whose source segments aren't recoverable).
File Download From IP URL Via Curl.EXE — stage 1 all of selection_img
or:
Image|endswith: '\curl.exe'
OriginalFileName: curl.exe
File Download From IP URL Via Curl.EXE — stage 2 all of selection_ip
CommandLine|re: '://[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
File Download From IP URL Via Curl.EXE — stage 3 all of selection_http
CommandLine|contains: http
File Download From IP URL Via Curl.EXE — stage 4 all of selection_flag
or:
CommandLine|contains: ' -O'
CommandLine|contains: --output
CommandLine|contains: --remote-name
File Download From IP URL Via Curl.EXE — stage 5 not 1 of filter_main_ext
or:
CommandLine|endswith: .bat
CommandLine|endswith: '.bat'''
CommandLine|endswith: '.bat"'
CommandLine|endswith: .dat
CommandLine|endswith: '.dat'''
CommandLine|endswith: '.dat"'
CommandLine|endswith: .dll
CommandLine|endswith: '.dll'''
CommandLine|endswith: '.dll"'
CommandLine|endswith: .exe
CommandLine|endswith: '.exe'''
CommandLine|endswith: '.exe"'
CommandLine|endswith: .gif
CommandLine|endswith: '.gif'''
CommandLine|endswith: '.gif"'
CommandLine|endswith: .hta
CommandLine|endswith: '.hta'''
CommandLine|endswith: '.hta"'
CommandLine|endswith: .jpeg
CommandLine|endswith: '.jpeg'''
CommandLine|endswith: '.jpeg"'
CommandLine|endswith: .log
CommandLine|endswith: '.log'''
CommandLine|endswith: '.log"'
CommandLine|endswith: .msi
CommandLine|endswith: '.msi'''
CommandLine|endswith: '.msi"'
CommandLine|endswith: .png
CommandLine|endswith: '.png'''
CommandLine|endswith: '.png"'
CommandLine|endswith: .ps1
CommandLine|endswith: '.ps1'''
CommandLine|endswith: '.ps1"'
CommandLine|endswith: .psm1
CommandLine|endswith: '.psm1'''
CommandLine|endswith: '.psm1"'
CommandLine|endswith: .vbe
CommandLine|endswith: '.vbe'''
CommandLine|endswith: '.vbe"'
CommandLine|endswith: .vbs
CommandLine|endswith: '.vbs'''
CommandLine|endswith: '.vbs"'
Suspicious File Download From IP Via Curl.EXE — stage 6 all of selection_img
or:
Image|endswith: '\curl.exe'
OriginalFileName: curl.exe
Suspicious File Download From IP Via Curl.EXE — stage 7 all of selection_ip
CommandLine|re: '://[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
Suspicious File Download From IP Via Curl.EXE — stage 8 all of selection_http
CommandLine|contains: http
Suspicious File Download From IP Via Curl.EXE — stage 9 all of selection_flag
or:
CommandLine|contains: ' -O'
CommandLine|contains: --output
CommandLine|contains: --remote-name
Suspicious File Download From IP Via Curl.EXE — stage 10 all of selection_ext
or:
CommandLine|endswith: .bat
CommandLine|endswith: '.bat'''
CommandLine|endswith: '.bat"'
CommandLine|endswith: .dat
CommandLine|endswith: '.dat'''
CommandLine|endswith: '.dat"'
CommandLine|endswith: .dll
CommandLine|endswith: '.dll'''
CommandLine|endswith: '.dll"'
CommandLine|endswith: .exe
CommandLine|endswith: '.exe'''
CommandLine|endswith: '.exe"'
CommandLine|endswith: .gif
CommandLine|endswith: '.gif'''
CommandLine|endswith: '.gif"'
CommandLine|endswith: .hta
CommandLine|endswith: '.hta'''
CommandLine|endswith: '.hta"'
CommandLine|endswith: .jpeg
CommandLine|endswith: '.jpeg'''
CommandLine|endswith: '.jpeg"'
CommandLine|endswith: .log
CommandLine|endswith: '.log'''
CommandLine|endswith: '.log"'
CommandLine|endswith: .msi
CommandLine|endswith: '.msi'''
CommandLine|endswith: '.msi"'
CommandLine|endswith: .png
CommandLine|endswith: '.png'''
CommandLine|endswith: '.png"'
CommandLine|endswith: .ps1
CommandLine|endswith: '.ps1'''
CommandLine|endswith: '.ps1"'
CommandLine|endswith: .psm1
CommandLine|endswith: '.psm1'''
CommandLine|endswith: '.psm1"'
CommandLine|endswith: .vbe
CommandLine|endswith: '.vbe'''
CommandLine|endswith: '.vbe"'
CommandLine|endswith: .vbs
CommandLine|endswith: '.vbs'''
CommandLine|endswith: '.vbs"'
Indicators (across all members)
| Field | Kind | Value | Members | Corpus |
|---|---|---|---|---|
CommandLine | ends_with | .bat | 2 | 5 |
CommandLine | ends_with | .bat" | 2 | 5 |
CommandLine | ends_with | .bat' | 2 | 5 |
CommandLine | ends_with | .dat | 2 | 7 |
CommandLine | ends_with | .dat" | 2 | 5 |
CommandLine | ends_with | .dat' | 2 | 5 |
CommandLine | ends_with | .dll | 2 | 9 |
CommandLine | ends_with | .dll" | 2 | 6 |
CommandLine | ends_with | .dll' | 2 | 6 |
CommandLine | ends_with | .exe | 2 | 6 |
CommandLine | ends_with | .exe" | 2 | 5 |
CommandLine | ends_with | .exe' | 2 | 5 |
CommandLine | ends_with | .gif | 2 | 4 |
CommandLine | ends_with | .gif" | 2 | 2 |
CommandLine | ends_with | .gif' | 2 | 2 |
CommandLine | ends_with | .hta | 2 | 6 |
CommandLine | ends_with | .hta" | 2 | 5 |
CommandLine | ends_with | .hta' | 2 | 5 |
CommandLine | ends_with | .jpeg | 2 | 4 |
CommandLine | ends_with | .jpeg" | 2 | 2 |
CommandLine | ends_with | .jpeg' | 2 | 2 |
CommandLine | ends_with | .log | 2 | 3 |
CommandLine | ends_with | .log" | 2 | 2 |
CommandLine | ends_with | .log' | 2 | 2 |
CommandLine | ends_with | .msi | 2 | 5 |
CommandLine | ends_with | .msi" | 2 | 5 |
CommandLine | ends_with | .msi' | 2 | 5 |
CommandLine | ends_with | .png | 2 | 4 |
CommandLine | ends_with | .png" | 2 | 2 |
CommandLine | ends_with | .png' | 2 | 2 |
CommandLine | ends_with | .ps1 | 2 | 6 |
CommandLine | ends_with | .ps1" | 2 | 5 |
CommandLine | ends_with | .ps1' | 2 | 5 |
CommandLine | ends_with | .psm1 | 2 | 6 |
CommandLine | ends_with | .psm1" | 2 | 5 |
CommandLine | ends_with | .psm1' | 2 | 5 |
CommandLine | ends_with | .vbe | 2 | 7 |
CommandLine | ends_with | .vbe" | 2 | 5 |
CommandLine | ends_with | .vbe' | 2 | 5 |
CommandLine | ends_with | .vbs | 2 | 7 |
CommandLine | ends_with | .vbs" | 2 | 5 |
CommandLine | ends_with | .vbs' | 2 | 5 |
CommandLine | match | -O | 2 | 3 |
CommandLine | match | --output | 2 | 3 |
CommandLine | match | --remote-name | 2 | 3 |
CommandLine | match | http | 2 | 31 |
CommandLine | regex_match | ://[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3} | 2 | 5 |
Image | ends_with | \curl.exe | 2 | 19 |
OriginalFileName | eq | curl.exe | 2 | 11 |