Chinotto Python Backdoor Exfiltrating exec() Output via Base64 POST

Detects HTTP POST requests to a known suspicious endpoint ('/board.php') often used by the Chinotto Python backdoor. The rule monitors for outgoing web traffic containing 'data=' parameters or connections to known malicious domains, indicating potential exfiltration of base64-encoded command output.