Grixba Infostealer: GT_NET.exe from Public\Music, inf_g.dll Drop, Known Hash

Detects execution and activity associated with the Grixba infostealer (often linked to Play Ransomware / Jumpy Pisces operations). The rule monitors for the execution of 'GT_NET.exe' from suspicious locations like 'C:\Users\Public\Music\', the loading or creation of the 'inf_g.dll' modular payload, and identifies a specific known Grixba v3 SHA-256 hash.