HEAVYGRAM Telegram Bot Remote Command Execution

This rule detects potentially malicious behavior involving the Python interpreter spawning command-line shells (cmd.exe or powershell.exe), or interactions (creation/modification) with a specific file at 'C:\ProgramData\ur.txt'. This behavior is often associated with post-exploitation activities, staging, or script-based execution of malicious payloads.