Possible BabylonRAT periodic C2 beaconing to external host

This rule detects periodic network beaconing patterns consistent with BabylonRAT malware. It flags established TCP connections to external networks that occur at a frequency exceeding 5 connections within a 300-second window, which may indicate a C2 check-in mechanism. Due to the heuristic nature of this detection, it is recommended to tune the threshold and correlate with payload analysis or entropy inspection to reduce noise.