BlueMoon EK: Browser Spawns cmd/curl/PowerShell to Drop msgbox.exe
Detects the BlueMoon exploit kit's post-exploitation activity, specifically identifying when a Chromium-based browser process (chrome.exe or msedge.exe) initiates command-line tools such as cmd.exe, powershell.exe, or curl.exe to download and execute a secondary payload named 'msgbox.exe' within the user's temporary directory.
Sigma

