DarkMe post-hollowing crypto-theft, AV enumeration, and C2 activity from clspack
Detects suspicious activity associated with the DarkMe RAT, specifically targeting cryptocurrency wallet data files. The rule correlates file access to known wallet data paths by a hollowed process 'clspack.exe', followed by suspicious outbound network activity originating from that same process, and potentially preceded by WMI-based antivirus enumeration.
Microsoft Sentinel (KQL)

