UAT-11587 / Antino campaign IOC Sweep (known hashes, domains, URLs)
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
Microsoft Sentinel (KQL)

