Casbaneiro C2 activation triggered by browsing to targeted bank sites

This rule detects potential command and control (C2) beaconing activity associated with the Casbaneiro (Metamorfo) banking trojan. It looks for instances where a known suspicious process (RegSvcs.exe or mobsync.exe) performs network communication within 5 minutes of a web browser on the same device navigating to a targeted banking URL.