Qakbot HTTP C2 Check-in via POST to .php with Legacy UA
Detects HTTP traffic patterns characteristic of Qakbot (QBot) malware command-and-control (C2) communication. This rule monitors for POST requests to .php files featuring a specific hardcoded User-Agent (IE 7.0 on Windows NT 5.1), a 'Cookie' header, 'application/octet-stream' content type, and a request body length of at least 201 characters.
Suricata

