Mustang Panda OIC PlugX campaign IOC sweep: hashes, C2 IP, domains

This rule monitors endpoint telemetry for indicators of compromise (IOCs) associated with known malicious activity. It checks for file creation, process execution, and network connections that match a defined list of malicious file hashes (SHA256, SHA1, MD5), C2 IP addresses, and malicious domains or URL patterns.