Detects the execution of a renamed "NirCmd.exe" binary based on the PE metadata fields.
Read the full analysis on IntelFusions