Hannibal Stealer FileZilla recentservers.xml FTP credential harvesting

This rule detects when non-FileZilla processes attempt to read or access sensitive FileZilla configuration files, specifically 'recentservers.xml' or 'sitemanager.xml', which are known to store plain-text credentials for site connections. This behavior is indicative of credential harvesting.