PaperCut server log deletion or tampering post-exploitation

Detects the deletion, truncation, or modification of critical PaperCut server logs and application files (server.log, pcxboot_l.txt, .bin files). This activity is associated with attempts to conceal exploitation of PaperCut vulnerabilities (e.g., CVE-2026-82078/81578) by clearing logs or tampering with binaries, typically executed by the PaperCut application processes themselves (pc-app.exe or Java runtime).