Mercurial Grabber adminapp.exe from TEMP exfiltrating to Discord webhook
Detects the execution of the Mercurial Grabber malware component (adminapp.exe) running from a temporary directory while establishing an outbound network connection to a Discord webhook URL.
Splunk (SPL)

