rule Linux_Generic_Threat_af48ca6a {
meta:
author = "Elastic Security"
id = "af48ca6a-f632-4a14-80ee-1b201273653d"
fingerprint = "ffd2b7e7d2777ee12f59d6f243e4868bc72b81cc9a05091a91944bfd29a4d636"
creation_date = "2025-01-08"
last_modified = "2026-05-22"
threat_name = "Linux.Generic.Threat"
reference_sample = "0f25e70efca8d0a5c88b70b19a6eaab0e3edae075130c129c1cb1c1ddeeb87a8"
severity = 50
arch_context = "x86, arm64"
scan_context = "file, memory"
license = "Elastic License v2"
os = "linux"
strings:
$a1 = { D0 4D E2 01 50 A0 E1 00 40 A0 E1 02 00 00 9A 04 00 51 E3 00 A0 90 E5 01 00 00 1A 1C D0 8D E2 F0 8F BD E8 05 00 51 E3 04 10 D0 E5 08 10 8D E5 F9 FF FF 0A 05 70 D0 E5 00 00 57 E3 F6 FF FF 0A 07 }
condition:
all of them
}