ClawdBot Malware IOC Watchlist

This rule detects file and network indicators of compromise (IOCs) associated with the fake 'ClawdBot Agent' VS Code extension malware campaign. It looks for known malicious file hashes and network connections to C2 infrastructure, including specific C2 checks for ScreenConnect relay on port 8041.