rule APT1_WEBC2_AUSOV { meta: author = "AlienVault Labs" info = "CommentCrew-threat-apt1" strings: $1 = "ntshrui.dll" wide ascii $2 = "%SystemRoot%\\System32\\" wide ascii $3 = "