BRIDGEHEAD main.exe modified ChaCha20 constant 'expad 232-byte k'

Detects the presence of the BRIDGEHEAD malware based on its unique Rust-compiled implementation of ChaCha20, specifically identifying a non-standard initialization string and a known hash associated with a decrypted in-memory payload.