Obfuscated PowerShell OneLiner Execution

 Original Source: [Sigma source]
Title: Obfuscated PowerShell OneLiner Execution
Status: test
Description:Detects the execution of a specific OneLiner to download and execute powershell modules in memory.
References:
  -https://thedfirreport.com/2022/05/09/seo-poisoning-a-gootloader-story/
  -https://gist.github.com/mgeeky/3b11169ab77a7de354f4111aa2f0df38
Author: @Kostastsale, TheDFIRReport
Date: 2022-05-09
modified:2025-04-16
Tags:
  • -'attack.execution'
  • -'attack.defense-impairment'
  • -'attack.t1059.001'
  • -'attack.t1685'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection:
    Image|endswith: '\powershell.exe'
    CommandLine|contains|all:
      -'http://127.0.0.1'
      -'%{(IRM $_)}'
      -'Invoke'

  condition:selection
Falsepositives:
  -Unknown
Level: high