MQTTDoor/MatrixDoor C2 beaconing via MQTT, Matrix, ip-api.com

Detects potential C2 activity associated with MQTTDoor or MatrixDoor malware by monitoring suspicious network traffic patterns. This includes unauthorized processes connecting to MQTT brokers (hivemq.com), non-chat applications interacting with a Matrix homeserver, and geo-location lookups (ip-api.com) occurring shortly after process execution.