Notepad++ The Chrysalis Backdoor

This rule detects activity related to the Chrysalis Backdoor, which is associated with the Lotus Blossom threat group. It identifies malicious activity through three main components: 1. File and process events matching a list of known malicious SHA256 hashes. 2. Network connections to known malicious IP addresses or domains. 3. Suspicious execution of 'svchost.exe' from non-standard Windows directories with specific command-line arguments, indicating potential masquerading or malicious execution.