DragonForce secondary C2 beacon to compromised WordPress theme PHP endpoint - anomalous structure

This rule detects anomalous GET requests to PHP files within the WordPress themes directory that match the specific pattern used by the DragonForce threat actor for secondary C2 beaconing. The detection identifies requests that lack typical WordPress request indicators like cookies or specific form fields, suggesting non-browser, programmatically generated C2 traffic.