Reverse SSH tunnel establishment to CARBONATO Costa Rica C2 relay

Detects outbound connections to a known malicious C2 infrastructure associated with the CARBONATO threat actor. The rule identifies both established SSH sessions using the OpenSSH implementation and the initiation of outbound TCP connections on ports dynamically determined by an MD5 hash, which is a known behavior of this actor's C2 communication strategy.