IronToll Iron Man System Phishing Kit HTTP Response Fingerprint

Detects the Iron Man System phishing kit via its HTTP fingerprint: a request-header rule (ETag/Server/Via combo) checked on the external server's response, and three request-side rules checking for the kit's hashed asset paths and favicon when an internal host requests them from an external site. Fixed a direction bug on the three request-side rules that had source/destination reversed (they previously required an external host to request the path from an internal server, which would rarely if ever fire).