SourTrade Malvertising - /config Response with Build Recipe JSON Fields and Base64 PE Header

This rule detects HTTP response bodies containing indicators associated with SourTrade malvertising campaigns, specifically JSON configuration fields and a base64-encoded Windows PE executable header (MZ/TVqQAAMAAAAEAAAA).