Detects execution of renamed version of PAExec. Often used by attackers
Read the full analysis on IntelFusions