Threat report

www.elastic.co/security-labs/threat-command/telepuz-maas-malware-clickfix

https://www.elastic.co/security-labs/threat-command/telepuz-maas-malware-clickfix
Published on
www.elastic.co

ATT&CK techniques those detections carry

  • T1059Command and Scripting Interpreter
  • T1059.001PowerShell
  • T1059.003Windows Command Shell
  • T1105Ingress Tool Transfer
  • T1204User Execution
  • T1204.004Malicious Copy and Paste
  • T1218System Binary Proxy Execution
  • T1218.005Mshta
  • +6 more
Open the original

2 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
Potential FileFix Command via Windows Explorer Address BarHigh
Potential ClickFix Command via Windows Run DialogHigh

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice