ET MALWARE QuickResponseC2 Default Response Struct
Query · suricata
flow:established,to_server; xbits:isset,ET.QuickResponseC2.Checkin,track ip_pair; http.method; content:"POST"; http.uri; content:"/result"; startswith; fast_pattern; pcre:"/^\d+\x5f\d+/R"; content:".png"; endswith; http.header; content:"Accept-Encoding|3a 20|gzip|2c 20|deflate|0d 0a|Accept|3a 20 2a 2f 2a 0d 0a|Connection|3a 20|keep-alive|0d 0a|Content-Type|3a 20|image|2f|png|0d 0a|Content-Length|3a 20|"; target:src_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata xbits
ET.QuickResponseC2.Checkin