logo

Actionable Threat Intel (IV) - YARA beyond files: extending rules to network IoCs

ID: 02e40e87-37e1-5aa3-bfb3-f80e8f74f478

STIX ID: report--02e40e87-37e1-5aa3-bfb3-f80e8f74f478

Feed Name: VirusTotal Blog

Date Published: 2023-07-24

Date Updated: 2026-05-01

Author: Alexandra Martin

...
...

VirusTotal unveils YARA Netloc, extending YARA hunting to network entities (domains, URLs, IPs) via the vt.net attribute and Livehunt, with templates and community rules to accelerate adoption. The post showcases practical detections—monitoring domains distributing malware, flagging Cobalt Strike C2 by default SSL certificate thumbprint, and identifying Telegram-based exfiltration URLs linked to stealer activity—highlighting how to combine network signals with VirusTotal metadata for proactive infrastructure tracking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.