Shellcode dynamic API resolution leading to urlmon.dll load and staging IP downl

Detects anomalous behavior indicative of the GRAYRABBIT shellcode which uses manual module walking and hash-based API resolution to load 'urlmon.dll' dynamically, followed shortly by an outbound network connection to a known malicious staging IP. This pattern reflects an evasion technique designed to avoid static import table analysis.