BotHelper C2 download-and-execute or plugin DLL fetch via /uploads path
Detects potential command and control (C2) activity associated with the BotHelper malware. The rule correlates a process downloading files or DLL plugins from specific C2 URL paths ('/uploads/Files/' or '/uploads/Plugins/') with a subsequent report of task execution status ('task_run.php' or 'task_failed.php') originating from the same process within a 10-minute window.
Microsoft Sentinel (KQL)

