Obfuscated hidden-window batch file chaining curl/mkdir/tar/schtasks in Temp
Detects the execution of batch files from temporary directories that employ command obfuscation techniques such as environment variable substring expansion, or which execute with a hidden window in conjunction with chained system utilities commonly associated with malicious activities (e.g., curl, tar, schtasks). This behavior is often indicative of staged payload delivery and execution.
Sigma

