id: ares-rat-c2 info: name: Area Rat C2 - Detect author: pussycat0x severity: info description: | Ares is a Python Remote Access Tool. reference: - https://github.com/montysecurity/C2-Tracker/blob/main/tracker.py metadata: verified: true max-request: 1 shodan-query: product:'Ares RAT C2' tags: c2,ir,osint,ares,panel,rat http: - method: GET path: - '{{BaseURL}}/login' matchers-condition: and matchers: - type: word part: body words: - '