Malicious PDF-disguised LNK via explorer.exe COM Factory Embedding (E4del)
This rule detects the execution of Windows Explorer (explorer.exe) with specific command-line arguments involving a factory initialization sequence and an embedding flag. This command line pattern is typically associated with shell object manipulation or specific COM object instantiation, which may be leveraged for process injection or hiding malicious activity.
CQL

