Suspicious Get-Variable.exe Creation (0c3fac91-5627-46e8-a6a8-a0d7b9b8ae1b)
Get-Variable is a valid PowerShell cmdlet WindowsApps is by default in the path where PowerShell is executed. So when the Get-Variable command is issued on PowerShell execution, the system first looks for the Get-Variable executable in the path and executes the malicious binary instead of looking for the PowerShell cmdlet.