UNK_DoubleCheck Rust loader: SysPr.prx sideload to Cloudflare R2
This rule detects the concurrent existence of specific process names (calibre-launcher.dll or wint.exe) and a specific file (SysPr.prx) on a device, combined with network connections to a specific Cloudflare R2 bucket. This pattern is indicative of potential malware activity involving suspicious DLLs, file drop-offs, and communication with remote infrastructure.
Microsoft Sentinel (KQL)

