Grixba Infostealer - inf_g.dll Load or Execution from Public Music Drop Path
Detects the loading or execution of the Grixba infostealer payload 'inf_g.dll' or processes executing from the known Grixba RDP drop path located at 'C:\Users\Public\Music\'. Grixba malware, associated with the Play ransomware group, often disguises its components to appear like legitimate software (e.g., SentinelOne). The rule filters out legitimate module loads occurring from authorized SentinelOne installation paths to reduce noise.
Sigma

