curl.exe downloads update_ms.msi to ProgramData over HTTP on port 443

Detects the use of curl.exe to download an MSI file (update_ms.msi) from a remote HTTPS source into the ProgramData directory. This pattern is commonly observed in malware delivery campaigns attempting to deploy payloads in a location with lower access restrictions.