Word Dropper | parent_name:winword.exe AND process_name:powershell.exe AND netconn_count:[1 TO *] |
PowerShell Second Stage | (domain:pastebin.com) and process_name:powershell.exe |
PowerShell Second Stage | process_name:powershell.exe AND filemod:ProgramData\*.exe |
PowerShell Downgrade | modload:windows\assembly\nativeimages_v*_32\*\*\system.management.automation.ni.dll and parent_name:powershell.exe AND netconn_count:[1 TO *] -cmdline:windows\\ccmcache* |
PowerShell Downgrade | modload:windows\assembly\nativeimages_v*_32\*\*\system.management.automation.ni.dll and parent_name:powershell.exe AND childproc_name:csc.exe and -cmdline:windows\\ccmcache* |