Multiple Payloads Delivered from Known C2 Infrastructure

This rule detects multiple outbound network connections to a specific set of known malicious C2 IP addresses on specific ports within a one-hour window. This behavior is indicative of a multi-payload delivery pattern associated with malware families such as Remcos, Agent Tesla, and RedLine.