MovieReaper Loader Respawn from Telemetry Masquerade Path Bypassing Anti-Sandbox
Detects the execution of the MovieReaper malware loader, which masquerades as 'msedge.exe' within the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This technique is used to bypass anti-sandbox checks by respawning as a legitimate-looking process in a persistent location after initial environment analysis is completed.
Sigma

