TinyRCT Sandbox Evasion: Short-Lived Downloads Process and choice.exe Self-Delete

This rule detects two suspicious behaviors associated with the TinyRCT malware family: the execution of common installer or archiver utilities in the Downloads folder that terminate within two seconds, and the use of 'choice.exe' for self-deletion of an executing process within a short timeframe.