Emotet C2 HTTP Callback - Random URI Segments with Form-Encoded Body

Detects outbound HTTP POST requests to external networks that match a known Emotet C2 traffic pattern. The rule specifically looks for HTTP POST requests using an 'application/x-www-form-urlencoded' Content-Type and a URI structure consisting of randomized alphanumeric segments (4-20 characters long). This structure is characteristic of Emotet's communication with its command-and-control infrastructure.