Phoenix Malware Detection

This rule detects the presence of Phoenix malware by identifying known SHA256 hashes of its components or network connections to its command and control (C2) infrastructure. It correlates file events with known malware hashes and network events with known C2 IP addresses.