RatHat mobile malware C2 API endpoint pattern over HTTP

Detects network activity associated with the RatHat Android malware agent, including C2 tasking, Go agent 'frpc' tunnel configuration retrieval, tunnel deployment status reporting, and internal loopback C2 server communication.