Payload staged as 8bfa.zip/8bfa.bin in Temp directory

This rule detects the creation of files with specific names '8bfa.zip' or '8bfa.bin' within the Windows AppData Local Temp directory. This behavior is indicative of a threat actor staging payloads or tools on a compromised system, typically as a precursor to execution or lateral movement.