Kamasers DDoS Botnet IOC Match (Network/File/Process)

This rule monitors endpoint network events, file events, and process executions for indicators associated with the Kamasers malware. It specifically looks for connections to known malicious C2 IP addresses and domains, as well as the presence or execution of files matching known malicious SHA256 hashes.