ZigCryptoStealer NativeAOT loader with BNB Smart Chain C2 resolution

This rule detects the presence of ZigCryptoStealer malware deployed via a NativeAOT-compiled Windows executable. The detection relies on identifying specific hardcoded infrastructure strings, such as a BNB Smart Chain RPC endpoint and a specific contract address used to resolve C2 domains. It also looks for common sideloading hosts associated with the malware's delivery.