UNC5142 Cloudflare Pages Lure leading to Command Execution

Detects a sequence of events where a user visits a Cloudflare Pages URL (*.pages.dev) and shortly after, a suspicious command (mshta, powershell, or curl) is executed. This pattern is consistent with the UNC5142 threat actor's TTP of using social engineering lures hosted on Cloudflare Pages to trick users into running malicious commands.