Possible StealC/Amadey stealer log exfiltration via HTTP POST to .php C2 beacon URI
This Suricata rule detects potential exfiltration of stolen data by the StealC or Amadey malware families. It specifically looks for an HTTP POST request to a .php URI containing a 'PK' header (the magic bytes for a ZIP file), suggesting the transmission of compressed stolen logs to a C2 server.
Suricata

