SilverFox api.php dispatcher Referer-based payload branching
Detects network activity associated with the 'SilverFox' malware family's command-and-control relay dispatcher. The rules identify specific HTTP requests to 'api.php', responses containing 'download_link', and the serving of legitimate WeChat installer payloads as a fallback mechanism for evasion, including the use of cache-busting parameters.
Suricata

