ET POLICY curl User-Agent Outbound ET HUNTING curl User-Agent to Dotted Quad ET MALWARE Win32/IcedID Request Cookie ET POLICY PE EXE or DLL Windows file download HTTP ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response
ET MALWARE Win32/IcedID Request Cookie ET POLICY curl User-Agent Outbound ET HUNTING curl User-Agent to Dotted Quad ET POLICY PE EXE or DLL Windows file download HTTP ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response
ET INFO Executable Download from dotted-quad Host ET HUNTING Suspicious BITS EXE DL From Dotted Quad ET POLICY PE EXE or DLL Windows file download HTTP ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response
ET INFO DNS Query for Suspicious .icu Domain ET INFO Suspicious Domain (*.icu) in TLS SNI SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) ET INFO TLS Handshake Failure