GRAYRABBIT Loader ADS Rename Self-Delete via SetFileInformationByHandle

Detects a specific self-deletion technique used by the GRAYRABBIT loader, which utilizes NTFS Alternate Data Streams (ADS). The malware uses SetFileInformationByHandle with FileRenameInfo to rename the file to an ADS (colon-delimited), followed by FileDispositionInfo to mark the file for deletion upon handle closure, effectively bypassing standard file deletion alerts. This rule is scoped to processes originating from common user-writable or temporary directories while excluding known legitimate software installers.