GRAYRABBIT system-info beacon connection to C2 mail.uaiubifas[.]top:443

Detects network communication to known malicious infrastructure associated with the GRAYRABBIT malware campaign. The rule correlates TCP connections on port 443 to the domain 'mail.uaiubifas.top' with process events attempting to discover system and user information (GetAdaptersAddresses, gethostname, GetUserNameA), which is characteristic of the malware's initial beaconing behavior.