C2Looper v2: wtsapi32.dll Sideload into OneDrive.exe + GitHub C2

This rule detects activities associated with the C2Looper v2 backdoor, which achieves persistence and code execution by sideloading a malicious wtsapi32.dll into the OneDrive process. It also identifies subsequent beaconing behavior where the compromised OneDrive process communicates with GitHub-hosted infrastructure to exchange command and control state files (cmd.json, result.json, beacon.json) instead of using traditional dedicated C2 servers.