SynkLoader Known Stage File Hashes (MSI/PS1/DLL)

This rule detects the presence of files known to be part of the SynkLoader malware delivery chain by matching their SHA256 hashes. It specifically identifies a malicious MSI installer, a Python-based loader (ss.py), and a fake msvcp150.dll runtime file used for DLL side-loading.