Payload reconstruction via copy /b of header.doc+body.doc into Windowsupdate.exe

Detects the use of the Windows 'copy /b' command to join multiple files into a single executable, specifically targeting patterns where document files are merged with a binary named 'Windowsupdate.exe'. This technique is often used to reassemble malicious payloads by combining split components or masquerading malicious content within seemingly benign file operations in temporary user directories.