PAPERMILL Hackers Abuse Signed Notepad++
Detects the loading of 'libcurl.dll' or related DLL patterns from suspicious directories such as '\Microsoft\Crypto\RuntimeBroker\', often associated with process masquerading or side-loading activities. The rule also monitors for the execution of suspicious binaries ('Tax_Notice_45594.exe') or binaries that mimic 'Notepad++' metadata from within these paths.
Microsoft Sentinel (KQL)

