MSBuild.exe LOLBin C2 connection to 212.34.141.103:4521
This rule detects instances of MSBuild.exe executing or communicating over the network while referencing .NET Framework paths. MSBuild is often abused as a LOLBAS (Living Off the Land Binary and Script) to execute arbitrary code or bypass application control, and unusual network activity from this process is a common indicator of beaconing or command-and-control communication.
Microsoft Sentinel (KQL)

