This time, the malicious C# code downloads an "icon" from a remote server, copies its binary content to newly allocated memory with execute permissions & executes it. This is textbook shellcode injection. The code in the picture has been modified in order to fit the whole logic.