APT36 PowerShell download of RUSTYSHADE via Backblaze (DriverInstaller.zip)
This rule detects the use of PowerShell to download a specific payload associated with the RustyShade malware from a Backblaze B2 cloud storage bucket. It monitors command lines containing 'wget' or 'Invoke-WebRequest' targeting 'f005.backblazeb2.com' and files named 'DriverInstaller.zip'.
Splunk (SPL)

