Emotet Malware HTTP GET with JNDI URI Patterns and Identity Encoding

Detects HTTP GET requests originating from internal network hosts to external destinations that match known Emotet C2 communication patterns, specifically those using hardcoded URI paths such as '/wp-content/', '/wp-admin/', or '/tmp/' combined with the 'Accept-Encoding: identity' header.