Emotet Malware HTTP C2 POST with Binary PE Payload Response
Detects outbound HTTP POST requests to suspicious URIs and subsequent inbound responses containing executable binary (PE) signatures, characteristic of Emotet malware command-and-control (C2) activity.
Suricata

