MovieReaper Loader RWX Shellcode Staging via VEH Hijack and C2 Download
This rule detects the execution of a specific known malicious file (identified by MD5 hash A0B13781EDD7CFDAB13D79AFFF3C83C1) followed by an outbound network connection to a suspicious IP address (193.23.118.155) or domain (deadhub.org) within a 10-minute window. This behavior is indicative of a malicious loader establishing a command and control (C2) channel.
CQL

