APT28 COM Hijack Persistence via EhStoreShell.dll

This rule detects potential COM hijacking of the CLSID InprocServer32 registry keys or unauthorized loading/creation of the 'EhStoreShell.dll' file. These behaviors are common indicators of persistence mechanisms or DLL side-loading where attackers redirect legitimate system calls to malicious code.