Google Quick Share Spawning System Shell - Possible Exploitation
Detects the loading of an unsigned DLL by 'quick_share.exe', 'NearbyShare.exe', or 'nearby_sharing.exe' from suspicious directory paths such as User Temp, AppData, or Downloads folders. This behavior is highly indicative of DLL side-loading attempts where an adversary leverages a legitimate, known process to execute malicious code.
SentinelOne

