HUNT Known C2 (php.shin_webshell, ClearFake, IClickFix, Unknown Loader, RevStealer, Cobalt Strike, AdaptixC2, ValleyRAT, AsyncRAT, Remus, VShell, Aisuru, Sliver, DCRat, PureRAT, Evilginx, Chaos, DanaBot, Tsundere, Mozi, Vidar, Stealc, magecart)

Detects outbound network connections to domains, URLs, and IP:Port combinations identified as malicious in the ThreatFox OSINT feed. This rule covers various commodity malware C2 and payload delivery infrastructure.