Analytics BIOC Low

ClickFix - PowerShell executed through the run application

An attacker may be trying to trick a user to execute PowerShell through the run application.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Execution (TA0002) Initial Access (TA0001)
ATT&CK techniques: User Execution (T1204) Phishing (T1566)
Attacker's goals:

An attacker may be trying to trick a user to execute PowerShell through the run application.

Investigative actions:

Check if the command line is known in the organization or malicious. And ask the user what is the source of it.

Test period:
N/A (single event)
Deduplication:
1 Day
4 variations:
  • ClickFix - PowerShell command executed through the run application and using Invoke-Expression cmdlet High (parent: Low)
  • ClickFix - Long PowerShell command executed through the run application with URL in the command High (parent: Low)
  • ClickFix - Long encoded PowerShell command executed through the run application High (parent: Low)
  • ClickFix - Schedule task PowerShell command executed through the run application High (parent: Low)