ERAAgent.exe stages and executes decompressed secondary payload

Detects behavior where the ERAAgent process writes a file to disk and executes that same file shortly after (within 5 minutes). This pattern is consistent with staged payload delivery, decompression, or assembly often observed in malicious activity, specifically referencing SLEEPWALKER malware patterns.