EtherHiding: JSON-RPC eth_call to BSC testnet contract via publicnode

This rule detects malicious network traffic generated by the ClearFake malware, which uses a specific JSON-RPC 'eth_call' request to the Binance Smart Chain (BSC) testnet to retrieve C2 instructions from a designated dead-drop smart contract. This method allows the adversary to maintain persistent command and control communication by leveraging blockchain technology.