APT28 Pawn Storm PRISMEX C2 via HTTP PUT to filen.io
Detects outbound HTTP PUT requests to 'filen.io', which has been associated with command-and-control (C2) communication for the PRISMEX malware used by the threat actor APT28 (also known as Pawn Storm/Fancy Bear).
Suricata

