APT28 Process Injection into svchost.exe with filen.io C2 Callback

Detects suspicious OpenProcess calls initiated by common user applications (explorer.exe, winword.exe, outlook.exe) targeting svchost.exe, followed by an outbound network connection from the target svchost.exe to the file sharing service filen.io within a 30-minute window. This behavior is indicative of process injection used to facilitate network communication or data exfiltration under the guise of a system process.