Once in a BlueMoon: Known-Malicious File Hash Hunt (BlueMoon Exploit Chain)

This rule detects the presence of files or process execution events matching a known set of SHA256 hashes associated with the BlueMoon malware family. The detection covers both file system events and process creation events.