This approach may have significant issues with 3rd-party antivirus and endpoint monitoring solutions, because this code is effectively indistinguishable from a malware dropper - "I just simply download an EXE to $TEMP, extract it, and it starts replacing binaries"
0 likes 1 replies
?