IronToll WebSocket Upgrade to Known C2 IP - Possible Live OTP/Credential Relay
Detects outbound WebSocket upgrade requests from internal network assets to known IronToll C2 IP addresses, restricted to requests whose Host header ends in one of the disposable TLDs observed across the campaign's 73+ rotating lookalike domains (.cfd, .sbs, .shop, .icu, .buzz, etc). This narrows the alert to the campaign's actual phishing-domain pattern rather than any WebSocket traffic that happens to reach the same shared Tencent/Alibaba cloud IPs, and a per-source threshold caps repeat alerts from the same host to one per hour.
Suricata

