Turla STOCKSTAY Payload Download via Web Proxy or DNS

This rule detects network activity involving known suspicious domains and the download of specific, potentially malicious files (archives and installers). The monitoring focuses on HTTP/proxy/DNS traffic where hostnames, URLs, or query parameters match indicators of malicious activity.