SynkLoader: MSI Masquerading as PowerShell Cleaner Drops Staged Payload
Detects the execution of a malicious MSI installer file named '331.msi' masquerading as a 'PowerShell Cleaner' utility. The rule monitors for the execution of this MSI package and the subsequent staging of suspicious files, specifically 'cleaner.ps1' and 'archive6.zip', within the '%LocalAppData%\PowershellCleaner\script\' directory.
Sigma

