MuddyWater Fakeset Backdoor: Python from Non-Standard Path with Public IP Outbound

This rule identifies instances where python.exe or python3.exe executes from non-standard system paths and establishes an outbound network connection to external (non-private/non-loopback) IP addresses. This behavior is indicative of potential malicious activity, as legitimate applications typically execute from protected program file directories, while adversaries often execute unauthorized binaries from temporary or user-writable locations to initiate command and control (C2) communication.