Sauron Loader installer chain file hashes (MSI/rnp.dll/tdwp.dll)
This rule uses YARA to identify specific malicious files associated with the Sauron Loader malware, including the MSI installer and associated support DLLs (rnp.dll, tdwp.dll), based on their known SHA-256 hashes.
YARA

