Backdoor put-command file drop via tempcache.tmp rename and MZ header patch
Detects the backdoor's put-command file-drop evasion: RtkNGUI64.exe creates tempcache.tmp then renames it to the target path before patching the corrupted MZ header bytes.
Microsoft Sentinel (KQL)

