Proxy Web Requests Matching Devil Bait C2 HTTP Parameters

Identifies proxy HTTP GET requests to /cross.php containing op, dt, and uid query parameters consistent with potential C2 traffic.

FreeReviewedSigma · High · v3
Category
proxy
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-15
Updated
2026-07-31

What it detects

This rule identifies HTTP GET requests routed through a proxy that contain specific URI query parameters consistent with Devil Bait C2 communication attempts. Such patterned web traffic can indicate command-and-control behavior where an implant retrieves or exchanges data via crafted endpoints. Detection relies on proxy telemetry capturing the HTTP method and the requested URI path/query string.

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-31

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.