GOMCam2024.exe decoy drop and throwaway Chrome profile launch

Detects instances where the GOMCam2024 executable launches or spawns a Chrome process with specific command-line arguments involving the user-data-directory being set to the system Temp folder. This behavior is often indicative of process injection, proxy-based credential theft, or attempts to execute browser sessions in a non-standard, potentially malicious context.