TonRAT Photo ZIP ClickFix: node.exe spawned from Downloads or TEMP/APPDATA

Detects the execution of Node.js from common user-writable directories like Downloads, TEMP, or APPDATA. This behavior is indicative of malicious implants, such as TonRAT or PureRAT, which often masquerade as legitimate tools or are delivered via phishing campaigns like Photo ZIP ClickFix, where a user is tricked into launching a payload from an untrusted location.