QakBot C2 HTTP Check-in - Alphanumeric PHP URI with Trident UA

Detects outbound HTTP POST requests characteristic of QakBot malware command and control (C2) activity. The rule identifies a specific combination of a hardcoded User-Agent string ('Trident/7.0') and a URI pattern consisting of 4 to 32 alphanumeric characters ending in .php.