Sourtrade Assembled Payload Bun Section Bytecode Entropy
Detects SourTrade browser-assembled malicious executables requiring the combination of a PE section named .bun, embedded JavaScriptCore bytecode reference (app.js), and anomalous high-entropy padding, distinguishing malicious assembled payloads from legitimate Bun single-file executables that contain a .bun section alone
YARA

