Outbound communication to known Akira ransomware GOST tunnel C2 IP

This rule detects outbound network connections directed at a known IP address associated with Akira ransomware infrastructure. The rule specifically monitors for communication with 64.227.4.134, which has been identified as a C2 node utilizing GOST tunnels. This behavior is indicative of established C2 connectivity by Akira ransomware actors.