C2Looper wtsapi32.dll side-loading via OneDrive.exe

This rule monitors for suspicious activity involving the OneDrive directory, specifically the file 'wtsapi32.dll'. It triggers when this DLL file is created, modified, or renamed within the OneDrive folder, followed by the termination of the OneDrive process, and subsequent loading of the same DLL file by that process. This pattern is indicative of a DLL side-loading attack where a legitimate application (OneDrive) is used to load a malicious DLL.