Qakbot C2 HTTPS on Non-Standard Port with Numeric IP SNI Pattern
This rule detects potential command and control (C2) activity related to the Qakbot malware. It specifically monitors for established outbound TLS traffic over non-standard ports (ports other than 443) where the Server Name Indication (SNI) field contains a numeric IPv4 address instead of a domain name, which is a characteristic behavior of Qakbot C2 infrastructure.
Suricata

