PureLogs Multi-Stage Chain: 3+ Correlated Behaviors in Short Window

Correlation detection for the PureLogs Stealer / fake Adobe Sign campaign. Fires when 3+ of 6 distinct attacker behaviors (Downloads-sourced 'output_*.js' execution via wscript/cscript, UserinitMprLogonScript persistence pointing at a .js payload, PowerShell fileless env-var payload reconstruction via [System.Environment]::GetEnvironmentVariable+IEX, in-memory .NET Assembly.Load without a disk-based .dll/.exe argument, PowerShell-initiated PixelDrain PNG retrieval, and PowerShell-initiated C2 traffic to vm180012.hosted-by.qwins.co) occur on the same host within a 15-minute window. All network/PowerShell legs are scoped to powershell.exe specifically to avoid flagging benign browser traffic to the legitimate PixelDrain file-sharing service.