← CatalogINDICATORPUBLIC INTELLIGENCE
URL https://researchcenter.paloaltonetworks.com/2017/03/unit42-pulling-back-the-curtains-on-encodedcommand-powershell-attacks/
Indicator published by the cited source.
Reference details
- Source context
turla/misp-turla-powershell-event.json- First reported
- Not reported
- Last reported
- Not reported
- Catalog updated
- 2026-10-08 08:01 UTC
Published indicators
Network addresses are displayed in defanged form.
URLhxxps://researchcenter[.]paloaltonetworks[.]com/2017/03/unit42-pulling-back-the-curtains-on-encodedcommand-powershell-attacks/
Source observations
- Evidence class
- published ioc
- Source family label
- Not reported
- Source confidence
- Not reported
- Observed
- Not reported
- Retrieved
- 2026-10-08 08:01 UTC
- Evidence class
- published ioc
- Source family label
- Not reported
- Source confidence
- Not reported
- Observed
- Not reported
- Retrieved
- 2026-10-08 06:20 UTC
- Evidence class
- published ioc
- Source family label
- Not reported
- Source confidence
- Not reported
- Observed
- Not reported
- Retrieved
- 2026-10-08 05:47 UTC