Sourtrade Assembled Payload Bun Section Bytecode Entropy

Detects SourTrade browser-assembled malicious executables requiring the combination of a PE section named .bun, embedded JavaScriptCore bytecode reference (app.js), and anomalous high-entropy padding, distinguishing malicious assembled payloads from legitimate Bun single-file executables that contain a .bun section alone