Sauron Loader DLL Embedded Config Header (magic 0xbaadf00d)

Detects the presence of an unpacked Sauron Loader DLL by identifying a specific embedded configuration header (magic value 0xbaadf00d followed by flags 0x40) in conjunction with configuration fields like 'group_id' or 'build_id'. This rule is intended for static analysis of file samples.