Browser-spawned newly-dropped executable execution (JSCEAL-style local assembly)
Detects a browser process (chrome.exe, msedge.exe, firefox.exe, brave.exe) writing a new, previously-unseen executable to a Downloads/Temp/Cache path and then launching that same executable within minutes — the terminal behavior of SourTrade's in-browser malware assembly pipeline, consistent with local execution of the JSCEAL (WeevilProxy) stealer payload.
Microsoft Sentinel (KQL)

