BlueMoon post-exploitation chain: chrome.exe->cmd.exe->curl.exe->msgbox.exe
Detects the use of 'curl.exe' to download a file named 'msgbox.exe' to the local temporary directory, specifically when triggered by 'cmd.exe' originating from 'chrome.exe'. This pattern is indicative of a browser-based delivery mechanism initiating a secondary malicious download.
Microsoft Sentinel (KQL)

