heroui logo

Potential TerminalFix Cloudflare Lure in PowerShell

Elastic Detection Rules

View Source
Summary
Detects PowerShell script blocks that print a fake Cloudflare verification lure as seen in TerminalFix campaigns. The rule flags events where a PowerShell script block text contains lure phrases such as "Cloudflare verification", "Cloudflare ID:", or "I am not a robot" in conjunction with actions indicating payload retrieval or execution (e.g., download, extraction, start-process, or hidden-window). It relies on powershell.file.script_block_text and correlates with event data from Windows PowerShell (Microsoft-Windows-PowerShell or PowerShellCore) and an Execute a Remote Command action, growing suspicion when the lure is followed by staging of a payload. This coverage aligns with MITRE ATT&CK techniques T1059.001 (PowerShell), T1204.004 (Malicious Copy and Paste), and T1189 (Drive-by Compromise) under Execution and Initial Access. The rule supports reconstruction of multi-fragment scripts across events (powershell.sequence, powershell.total, powershell.file.script_block_id) to determine if a payload is retrieved and executed, and emphasizes investigation fields including host.id, user.id, process.pid, and related path and destination evidence. It includes setup guidance for enabling PowerShell Script Block Logging, and provides triage, false-positive guidance, and remediation steps for suspected TerminalFix activity, including isolating hosts, terminating PowerShell instances, deleting payloads, and hardening logging to prevent pasting-based abuse. The rule has a high severity and risk score, appropriate for Windows endpoint monitoring of disruptive, multi-stage attacks using PowerShell.
Categories
  • Endpoint
  • Windows
Data Sources
  • Process
  • Script
ATT&CK Techniques
  • T1059
  • T1059.001
  • T1204
  • T1204.004
  • T1189
Created: 2026-09-28