AsyncRAT Payload Execution from Temp Directory

Detects execution of a specific suspicious executable file masquerading in the Windows Temp directory, coupled with the access of an associated .ini configuration file. This behavior is indicative of AsyncRAT deployment, often involving initial execution or staging of configuration files within volatile user directories.