Loader Injects/Resides Inside The Default Instance Of Windows Explorer.
Optional Melting Of Loader Executable After Injection.
Optional Custom Windows Defender Exclusions.
Optional Self-Updating And Uninstallation Of Loader Via HTTP/HTTPS.
Optional Dropping/Execution Of Multiple Payloads Via HTTP/HTTPS.
All Loader/Payload Actions Are Triggered By Changes In "Last-Modified" HTTP Response Header.
Optional Persistence With Registry, Startup Folder, Scheduled Task.