Spoofed Desktop Ini Whitespace C2
Detects a fake desktop.ini file combining a legitimate-looking ShellClassInfo/LocalizedResourceName lure (shell32.dll,-21781) with a C2 domain hidden as unary-encoded trailing whitespace after byte offset 174 -- consolidates the lure-content and whitespace-encoding indicators into one high-fidelity rule
YARA

