AiTM Phishing Proxy Artifact — Evilginx2/Tycoon2FA on Relay Host

This rule detects indicators of Adversary-in-the-Middle (AiTM) phishing infrastructure, specifically targeting Evilginx2 and similar proxy frameworks. It identifies unauthorized execution of Evilginx2 binaries, the presence of specific session and configuration files (.evilginx/, phishlets, session databases), unauthorized modifications to Nginx configurations, and the dropping of suspicious HTML lure files into web document roots by scripting interpreters.