ClickFix: Hidden cmd.exe Spawned by Beaconing Injected Process (StealC ClickFix)

This rule detects instances where a process associated with a known StealC command-and-control (C2) IP address subsequently spawns a hidden cmd.exe instance. It correlates network connections to known malicious infrastructure with the creation of hidden command shells within the same device session, specifically looking for common parent processes like web browsers or system utilities.