DeepLoad/BabaDeda - PowerShell Multi-Stage Loader Chain (ClickFix)

This rule detects a multi-stage loader chain behavior. Stage 1 identifies PowerShell spawning mshta.exe or wscript.exe, which is commonly used to execute malicious scripts or loaders. Stage 2 detects mshta.exe or wscript.exe subsequently executing schtasks.exe or wmic.exe with command-line arguments indicative of establishing persistence via scheduled tasks or WMI event subscriptions.