Rust stealer TLS/HTTP C2 relay contact (network log)

Detects network activity associated with Rust-based stealer malware, specifically focusing on connections to a known C2 IP address (31.76.7.137) or HTTP requests directed at static-asset paths (e.g., analytics.gif, pixel.png, content.js) when the destination is an IPv4-literal address. This behavior is indicative of C2 beacons or data exfiltration disguised as legitimate web traffic.