id: ares-rat-c2 info: name: Area Rat C2 - Detect author: pussycat0x severity: info description: | Ares is a Python Remote Access Tool. reference: - https://github.com/montysecurity/C2-Tracker/blob/main/tracker.py metadata: verified: true max-request: 1 shodan-query: product:'Ares RAT C2' tags: c2,ir,osint,ares,panel,rat http: - method: GET path: - '{{BaseURL}}/login' matchers-condition: and matchers: - type: word part: body words: - 'Ares' - 'Passphrase:' condition: and - type: status status: - 200 # digest: 4b0a00483046022100d549cbeeb7a487f749188b50a322105c7c2a816fb305094af8ce95f7a6e9f5d7022100faac50b6314eb3807976806b21d9e7bdd18111120c85315e051ff08d22941f3e:922c64590222798bb761d5b6d8e72950