TWINLOOT Arbitrary Command Fallback via pythonw.exe shell=True

Detects the TWINLOOT Python implant's arbitrary shell command handler, in which pythonw.exe running from a non-standard directory (ProgramData, AppData, or Temp) spawns cmd.exe with a /c argument and CREATE_NO_WINDOW creation flags, consistent with the implant's default command handler executing operator-tasked commands with a hidden console window.