Reflective In-Memory Loading of SloppyRAT DLL (No Disk Backing)

Detects potential reflective code loading or memory injection attempts within Python interpreter processes (pythonw.exe, ipy.exe). The rule monitors for processes that lack a valid module path or file path on disk while referencing known indicators of malicious memory-based loading, such as 'hostfxr.dll' or specific suspicious strings like 'DLLMemLoader'. This technique is often used to execute payloads directly in memory to evade file-based security controls.