Turla STOCKSTAY Malware RAR/ZIP Archive Download from Compromised UA Servers
Detects HTTP GET requests for specific malicious archives (calculator.rar, EditorToolsPdf.zip) originating from suspected compromised Ukrainian domains (basecon.com.ua, online.zp.ua). This behavior is associated with the STOCKSTAY malware used by the threat actor Turla.
Suricata

