MovieReaper PEB Ldr API Resolution Evasion via Shellcode C2 and Masquerade

Detects indicators of the MovieReaper loader, specifically the downloading of shellcode fragments disguised as image assets from known malicious C2 infrastructure, and the masquerading of a malicious binary as 'msedge.exe' within the Windows Telemetry folder for persistence. The rule specifically targets the loader's behavior of using PEB Ldr traversal to resolve APIs and evade hooking-based security controls.