GemStuffer XSS callback to OAST/webhook.site exfil endpoints

This rule detects network activity associated with the GemStuffer malware, specifically monitoring for DNS queries to known OAST callback domains, HTTP requests to specific C2 paths, and unauthorized data exfiltration attempts to the webhook.site service.