APT36 SHEETCREEP Melt: cmd.exe del /f Self-Deletion of Dropper EXE

Detects the SHEETCREEP malware's melt function, which uses a hidden 'cmd.exe' process to forcibly delete executables. This is characterized by 'cmd.exe' spawning with a specific command line pattern involving 'choice /C Y /N /D Y /T 2' for a delay, followed by 'del /f /q' to delete an .exe file. The rule also looks for file deletion events of .exe files initiated by 'cmd.exe' outside of the C:\Windows\ directory with 'del /f' or 'del /f /q' in the command line.