File concatenation via copy /b reconstructs Windowsupdate.exe from header.doc+body.doc in %LOCALAPPDATA%

Detects the use of the 'copy /b' command to reconstruct an executable payload (Windowsupdate.exe) by concatenating split decoy files (header.doc and body.doc) typically located within a _rels directory, a technique associated with malware delivery chains like Operation QUICSILVER.