vvs-stealer

This rule detects activities associated with the VVS Stealer malware, as described in the Palo Alto Networks Unit 42 blog. It identifies the malware through specific SHA256 hashes of known VVS Stealer executables, network connections to hardcoded Discord webhook URLs used for exfiltration, persistence mechanisms via creation of executables in Windows startup folders, creation of '_vault.zip' files (likely containing stolen data), and suspicious Discord-related process activity indicative of the stealer's operation.