rnpkeys.exe execution followed by HTTPS beacon (Sauron registration)
Detects execution of rnpkeys.exe from the C:\ProgramData\keyroll\ directory, which is indicative of Sauron Loader side-loading activity, followed by an outbound network connection on port 443 within a 5-minute window. This behavior is consistent with the initial bot registration beaconing phase of the malware.
YARA-L

