PowerShell Downloads HEAVYGRAM Payload from Vultr Object Storage

Detects the use of PowerShell to download files from Vultr Object Storage, specifically targeting patterns associated with the HEAVYGRAM malware distribution. The rule monitors for PowerShell cradles (WebClient, DownloadFile), archive extraction commands, or the execution of a specific payload name (RuntimeSSH.exe) often linked to the Handala Hack threat activity.