TrickBot C2 HTTP POST Check-in via /rob/ or /ins/ URI
Detects outbound HTTP POST requests with specific URI patterns (/rob/ or /ins/) that are indicative of TrickBot malware command and control (C2) check-in activity.
Suricata

Detects outbound HTTP POST requests with specific URI patterns (/rob/ or /ins/) that are indicative of TrickBot malware command and control (C2) check-in activity.

Already have an account?