C2Looper C2 traffic to known IPs over TCP/8888
Detects network connection events to specific known malicious IP addresses (45.158.196.23, 45.158.196.184) over TCP port 8888. This activity is indicative of potential command and control (C2) communication or unauthorized remote access.
Microsoft Sentinel (KQL)

