Casbaneiro/Ousaban Campaign IOC Match (C2 IPs, Domains, Subdomains)
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
Microsoft Sentinel (KQL)

