Lightlife RAT C2 beacon loop to 91.196.32.232 getcmd/post endpoints

This rule detects potential command-and-control (C2) activity by monitoring network connections to a specific malicious IP address (91.196.32.232) over port 8089 and correlating this with suspicious PowerShell commands. The rule looks for PowerShell scripts executing 'Invoke-RestMethod' to reach out to the C2, as well as obfuscated or beaconing-like behavior involving 'Start-Sleep' intervals paired with C2-related keywords.