Phantom Stealer known C2 IP infrastructure contacted

Detects network communication with known Command and Control (C2) IP addresses associated with Phantom Stealer malware. This rule monitors both outbound connections from the internal network and inbound traffic from the identified malicious infrastructure.