• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    ClickFix Fake Decryption Error Spawns Piped Shell/PowerShell Command

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•0

    Detects ClickFix-style social engineering attacks where users are prompted to copy and execute malicious commands in a shell environment. The rule triggers on process execution of terminal or shell binaries (zsh, sh, cmd.exe, powershell.exe) containing indicators of obfuscated execution or remote code downloading, such as piped shell commands (curl | sh/zsh) or PowerShell encoded command execution.

    YARA-L

    Tags

    T1059 - Command and Scripting InterpreterT1059.001 - PowerShellT1059.003 - Windows Command ShellT1059.004 - Unix ShellT1204.002 - Malicious FileTA0002 - ExecutionProcess CreationCommand ExecutionScript ExecutionWindowsmacOSLinuxWindows SysmonmacOS Endpoint Security Framework

    Found in

    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 22 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?