QakBot C2 HTTP POST Check-in with Encoded System Info and Version String

Detects HTTP POST requests characteristic of QakBot command-and-control check-ins. The rule looks for an 'established' flow to an external network using a POST method, with a request body containing 'qbot' followed by a version string pattern, which is indicative of the malware reporting system info to its C2 server.