Malicious PDF Editor Activity Detection

This rule detects outbound network connections to command and control (C2) domains and identifies files by name or hash associated with malicious PDF editor campaigns (e.g., ConvertMate, PDFClick, PDFSkills). These campaigns use malicious PDF editors for C2 communication, to download additional payloads, and for initial execution.