Bluekit BitM PhaaS - Browser Fingerprinting and Large Obfuscated JS Bundle

Detects potential browser fingerprinting and network reconnaissance behavior associated with Bluekit BitM PhaaS campaigns. The rule correlates large suspicious JavaScript file downloads (excluding common CDNs) with STUN server connectivity within a 10-minute window, a pattern often used by adversary-in-the-middle (AiTM) frameworks to fingerprint victims and establish WebRTC channels.