ClearFake EtherHiding malicious JS injection detected in HTTP response

This rule detects patterns characteristic of the ClearFake/EtherHiding campaign, specifically identifying the injection of malicious JavaScript within HTTP responses. The rule monitors for the creation of a script element and the use of base64-encoded javascript content, which is a known technique used in these attacks to facilitate drive-by compromises.