Dark Caracal GoCaracal Exec from Random Hex Folder in AppData Roaming
Detects the execution of an executable file located within a randomly-generated, hex-like directory structure directly beneath the %AppData%\Roaming folder. This pattern is characteristic of the GoCaracal malware dropper used by the Dark Caracal threat group to evade detection by hiding executables in paths that mimic temporary or system-generated folder structures.
Sigma

