QUICSILVER Windowsupdate.exe Backdoor Discovery Activity

Detects the execution of Windowsupdate.exe, a known component of the QUICSILVER campaign. The backdoor is identified by its filename and specific file hash. Once executed, it facilitates system and directory discovery, including hostname enumeration and file system navigation.