RANSOMWARE - Cicada3301 Affiliate C2 Check-In

Detects outbound HTTP POST requests associated with Cicada3301 ransomware affiliate check-in behavior. The rule monitors for a specific 'X-Session-Id' HTTP header and a corresponding 'affiliate_id' parameter within the request body, which are indicative of malicious C2 communication.