MovieReaper Loader PEB Ldr Traversal via Torrent-Spawned Movie Exec

This rule detects the execution of a file with a suspicious media-themed filename (e.g., related to 1080p, BluRay, etc.) from a known BitTorrent client process, followed by an immediate network connection to a known malicious C2 IP address or domain within a 10-minute window. This behavior is indicative of a user downloading and executing a malicious file disguised as pirated media.