• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Obfuscated PowerShell downloads configuration.ps1 via ClickFix (mnl.ac)

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•2

    Detects obfuscated PowerShell commands bypassing execution policy to download or execute 'configuration.ps1' or communicate with known malicious infrastructure associated with the ClickFix campaign. The rule specifically looks for caret-based obfuscation, bypass switches, and known IOCs in the command line.

    Splunk (SPL)

    Tags

    T1059.001 - PowerShellT1027 - Obfuscated Files or InformationT1140 - Deobfuscate/Decode Files or InformationTA0002 - ExecutionTA0005 - StealthProcess CreationPowershell Script ExecutionCommand ExecutionEDR AlertWindowsCrowdstrike Falcon EDRSentinelone EDRCarbonblack EDRspl

    Found in

    • ClickFix Campaign Targets News Outlet with StealCLast updated 22 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 22 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 22 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 22 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 22 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?