Python interpreter disguised as codeflush.exe (python.exe deleted, pythonw.exe r

Detects malicious file system activity where the legitimate Python interpreter (python.exe) is deleted and replaced or renamed to a deceptive filename (codeflush.exe) within the 'C:\Users\Public\Music\MusicLibrariesPackage' directory. This technique is used by threat actors, including APT37, to mask the execution of Python-based backdoors and evade detection.