Sality-style in-process remote thread creation for decrypted loader execution

Detects the Sality malware secondary loader creating a new thread within the same infected process, a technique known as self-injection, used to execute decrypted payloads. The rule specifically looks for 'CreateRemoteThreadApiCall' events where the initiating process ID matches the target process ID and correlates this behavior with the creation of mutexes associated with the Sality malware family.