ClickFix Cyrillic Homoglyph Obfuscation in PowerShell Script Blocks
This rule detects PowerShell script blocks containing a suspicious combination of Base64-like character sets and Cyrillic characters. This technique is often used in obfuscated payloads to evade static analysis signatures or to hinder human readability by inserting non-Latin characters within encoded content, which may trigger different parsing behaviors in various environments.
Sigma

