GRAYRABBIT C2 plugin download/reflective load via command 5 FileMsg chain
Detects behavior indicative of the GRAYRABBIT malware, specifically identifying network connections to known command-and-control (C2) infrastructure (mail.uaiubifas.top) followed within a short time window (10 minutes) by reflective in-memory module loading activities within the same process. This pattern suggests the delivery and execution of a plugin or additional malicious payload without writing the binary to disk.
Microsoft Sentinel (KQL)

