NjRAT Bladabindi C2 Pipe-Delimited ll/kl Command Detection

This rule detects network traffic indicative of the NjRAT (Bladabindi) remote access trojan, specifically identifying its pipe-delimited command-and-control protocol patterns (e.g., '|ll|' or '|kl|').