Maybe it was used as some sort of privilege escalation? E.g. NP++ downloads an XML file to %TEMP%, some already present malware modifies it, then GUP downloads a payload and executes it with administrator permissions.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments