MovieReaper Loader msedge.exe Masquerade C2 Beacon via VEH Shellcode Stage

Detects the Microsoft Edge browser executable running from an anomalous path (C:\ProgramData\Microsoft\Windows\Telemetry\) or exhibiting suspicious network behavior (to a known malicious domain 'deadhub.org' or IP address '193.23.118.155'). This behavior is indicative of a masquerading attempt to hide malicious activity by mimicking a trusted browser binary.