curl.exe copied from System32 and renamed for LOLBin download (RpJjgMB.exe)

Detects the copying of the legitimate Windows curl.exe binary from System32 to a user-writable directory (such as AppData\Local\Temp) and renaming it. This is a common LOLBin (Living Off the Land Binary) technique used by adversaries to disguise the utility as a benign application to evade detection while facilitating the download of second-stage payloads.