Kimsuky OrionQuests-Setup.exe Deceptive .NET Installer

Detects the execution of OrionQuests-Setup.exe, a .NET-based executable identified as a malicious installer used by the Kimsuky (APT-C-55/BabyShark) threat group. The rule flags PE files that match the specific filename and contain both .NET framework indicators and references to LNK files, suggesting the dropper mechanism for initial stage infection.