Suspicious Network Connection to Known APT C2 Ranges

This rule detects network connections from internal devices to identified APT Command and Control (C2) IP address ranges over common ports (8080, 443, 21, 22, 23, 25, 445). This traffic pattern is indicative of unauthorized external communication commonly associated with malware or adversary activity.