malwarebytes-windows-github-io virustotal
This rule detects the presence or execution of known malicious infostealer files based on their SHA256 hash values or a specific filename pattern. The SHA256 hashes are associated with infostealer malware as referenced in a VirusTotal blog post. The filename pattern 'malwarebytes-windows-github-io' also indicates potential malicious activity, likely related to a deceptive download or execution.
Microsoft Sentinel (KQL)

