Casbaneiro C2 DNS Query to Known Malicious Domain
Detects network communication associated with the Casbaneiro (Metamorfo) banking trojan, specifically identifying DNS queries, TLS SNI headers, HTTP Host headers, and direct IP connections to known malicious C2 infrastructure.
Suricata

