Mirage2FA Harvesting JS Loader Fetch via /xls/<token>.js Pattern

Detects HTTP GET requests to known Mirage2FA phishing infrastructure domains and specific URI patterns associated with the retrieval of JavaScript loaders. This rule monitors for specific URL paths ('/xls/') and naming conventions (e.g., 'a1p2i.js') characteristic of the Mirage2FA phishing kit, which is used to harvest 2FA tokens.