alert http $EXTERNAL_NET any -> $HOME_NET any (
msg:"ET MALWARE Drovorub cloud.auth Module Server Response";
flow:established,to_client;
file_data;
content:"|7b 22|children|22|"; startswith;
content:"|22|name|22|";
content:"|22|module|22|";
content:"Y2xvdWQuYXV0aA=="; distance:0; fast_pattern;
content:"|22|name|22|";
content:"|22|action|22|";
content:"|22|name|22|";
content:"|22|serverid|22|";
reference:url,media.defense.gov/2020/Aug/13/2002476465/-1/-1/0/CSA_DROVORUB_RUSSIAN_GRU_MALWARE_AUG_2020.PDF;
classtype:targeted-activity;
sid:2030683; rev:1;
metadata:affected_product Linux, attack_target Client_Endpoint, created_at 2020_08_13, deployment Perimeter, confidence High, signature_severity Major, updated_at 2020_08_13;
)