In this blog, read along as we investigate a malicious foothold and decode the payload step by step.