• SteveTech@aussie.zone
    link
    fedilink
    English
    arrow-up
    5
    ·
    17 hours ago

    Maybe it was used as some sort of privilege escalation? E.g. NP++ downloads an XML file to %TEMP%, some already present malware modifies it, then GUP downloads a payload and executes it with administrator permissions.