GRAYRABBIT file read followed by C2 upload to mail.uaiubifas[.]top
Detects potential data exfiltration activity associated with the GRAYRABBIT threat actor, where a local file is accessed or modified by a process shortly before or after that same process initiates a network connection to a known GRAYRABBIT C2 endpoint over port 443.
Microsoft Sentinel (KQL)

