ET MALWARE Likely Infected HTTP POST to PHP with User-Agent of HTTP Client
Query · suricata
flow:established,to_server; http.method; content:"POST"; nocase; http.uri; content:".php"; nocase; http.user_agent; bsize:11; content:"HTTP Client"; fast_pattern;