TWINLOOT fake loading-screen asset hot-linked from raw.githubusercontent.com by non-browser UA

This rule detects suspicious network connections to GitHub and Postimg where specific assets are retrieved by a non-browser User Agent. This behavior is associated with the TWINLOOT campaign, where a Python-based implant retrieves fake loading-screen assets as part of a C2 communication sequence, utilizing legitimate image and video hosting services as dead-drop resolvers.