1. The sample contains the unique markers EVIL_MARKER_7 and beacon=. Write:
rule detect {\n strings:\n $a = "EVIL_MARKER_7"\n $b = "beacon="\n condition:\n all of them\n}.
Why: the engine checks your strings: appear in the malicious sample and that the condition: holds there but NOT in the clean file. Unique markers give a selective rule.
2. Paste the rule; on a correct, selective match the flag appears.
Lesson: detection rules should key on stable, unique artifacts.