AsyncRAT Delivery - .NET Executable Spawning Network Connection to Non-Standard Port After Fake Installer

Detects processes running from suspicious, writable directories (Temp, AppData, Downloads) that simultaneously load the .NET Common Language Runtime (clr.dll) and initiate network connections. This behavior is indicative of a downloaded binary or payload executing managed code to perform C2 communication.