GRAYRABBIT silent process execution via infected 7z.exe (C2 cmd 0)

Detects child processes spawned by 7z.exe when it is executed from the 'C:\Users\Public\Documents\' directory. This is consistent with the behavior of the GRAYRABBIT backdoor, where a trojanized 7z.dll or boy.dll is sideloaded into the 7z.exe process to facilitate silent arbitrary process execution.