Malware C2 Domain Generation Algorithm (DGA) Detected

This rule detects potential Command and Control (C2) communication activity by identifying instances of Domain Generation Algorithms (DGA). It monitors DNS query responses for patterns consisting of 8 to 16 lowercase alphabetic characters followed by common TLDs (com, net, org, ru, cc, su). An alert is triggered if 5 or more unique suspicious domains are queried by the same device within a one-hour window.