Grixba Infostealer XOR-Encrypted DLL Staging and GT_NET.exe Execution
Detects the Grixba infostealer (associated with Play ransomware operations) by identifying the loading of the XOR-encrypted payload 'inf_g.dll' from commonly abused directories like Temp, AppData, ProgramData, or the Public folder, particularly when the file is unsigned.
Sigma

