rule:
meta:
name: get HTTP response content encoding
namespace: communication/http/client
authors:
- matthew.williams@mandiant.com
scopes:
static: basic block
dynamic: call
mbc:
- Communication::HTTP Communication::Get Response [C0002.017]
examples:
- FBBAAF569B63F6398503E4F1979CABEF:0x4068D9
features:
- and:
- api: wininet.HttpQueryInfo
- number: 0x1D = HTTP_QUERY_CONTENT_ENCODING
last edited: 2023-11-24 10:35:00