ET MALWARE FraudLoad.aww HTTP CnC Post
Query · suricata
flow:established,to_server; http.method; content:"POST"; nocase; http.uri; content:"/instlog/?"; nocase; fast_pattern; http.user_agent; content:"Mozilla/3.0 (compatible|3b 20|TALWinInetHTTPClient"; depth:45;