Ghostcontainer Net Backdoor Assembly

Detects the GhostContainer .NET-based backdoor assembly deployed on compromised Microsoft Exchange servers, requiring multiple corroborating unique indicators (C2 header, proxy class name, virtual path parameters) alongside .NET/PE structure to reduce false positives