Fire Ant Linux implant IOCs: TacTap, BridgeAgent, VMCI backdoor, SELinux downgra

This rule monitors security event logs for the presence of a specific file hash identified as potentially malicious (d41d8cd98f00b204e9800998ecf8427e). This hash specifically corresponds to an empty file (MD5 checksum of an empty string), often indicating potential obfuscation techniques, failed file writes, or placeholder files used by malicious scripts.