AsyncRAT C2 Default Port AES Payload Header Detection

Detects network communication associated with AsyncRAT command-and-control activity. The rule identifies established outbound connections on non-standard ports (6606, 7707, 8808) containing a specific 3-byte null sequence header, which is indicative of AsyncRAT's communication protocol.