Potential TerminalFix Cloudflare Lure in PowerShell
editPotential TerminalFix Cloudflare Lure in PowerShell
editIdentifies PowerShell script blocks that print a fake Cloudflare verification lure. TerminalFix pages instruct the victim to paste a command into Windows Terminal or PowerShell. The script presents messages such as "Cloudflare verification", "Cloudflare ID:", or "I am not a robot" while it stages a payload. Review the full script block for download, extraction, and follow-on execution.
Rule type: query
Rule indices:
- logs-windows.powershell*
- winlogbeat-*
Severity: high
Risk score: 73
Runs every: 5m
Searches indices from: now-9m (Date Math format, see also Additional look-back time)
Maximum alerts per execution: 100
References:
Tags:
- Domain: Endpoint
- OS: Windows
- Use Case: Threat Detection
- Tactic: Execution
- Tactic: Initial Access
- Data Source: PowerShell Logs
- Resources: Investigation Guide
- Threat: ClickFix
- Rule Type: Custom Query (KQL)
- Platform: Windows
Version: 1
Rule authors:
- Elastic
Rule license: Elastic License v2
Investigation guide
editTriage and analysis
Investigating Potential TerminalFix Cloudflare Lure in PowerShell
Possible investigation steps
- What lure text was executed, and what command sits around it?
- Why: TerminalFix pastes a multi-line PowerShell script that prints a fake Cloudflare check. Script block logging records that text even when the process command line only shows the host binary.
-
Focus:
powershell.file.script_block_textfor "Cloudflare verification", "Cloudflare ID:", or "I am not a robot", then the surrounding download, extract, start-process, or hidden-window statements. - Implication: escalate when the lure is paired with a download, archive extraction, encoded command, or a launch of another script, batch file, or executable. Lower suspicion only when the same text is a bounded lab reproduction with no retrieval or second stage.
- Is this fragment the whole script?
- Why: one pasted script can be split across multiple 4104 events.
-
Focus:
powershell.file.script_block_id,powershell.sequence, andpowershell.totalon the samehost.id. Order the fragments by sequence and read the reconstructed script. - Implication: escalate when a later fragment retrieves a payload, writes under a user-writable or ProgramData path, or starts a follow-on process. A single fragment that only prints the lure leaves the rest of the script unresolved.
- Did the script stage or launch a payload?
-
Focus: paths, URLs, and executables named in the reconstructed script. On the same
host.id, review file and process events in a tight window around the alert for archives, extracted directories,cmd.exe,powershell.exe, or an unexpected executable start. -
Hint: if
process.entity_idis absent, fall back tohost.idplusprocess.pid. - Implication: escalate when a file lands outside a recognized installer path, a batch or executable starts from that location, or the script reaches an unusual domain or IP. Missing file or network telemetry leaves those questions unresolved.
- How was this PowerShell instance started?
-
Focus: the process start for this
process.pidonhost.id, includingprocess.parent.name,process.parent.executable,process.command_line,user.id, anduser.name. - Implication: escalate when Windows Terminal, a console host, or explorer starts PowerShell for an end user just after browser activity. A scheduled admin task is lower suspicion only when the script content is that task and contains no lure-plus-payload behavior.
- Escalate when the Cloudflare lure is paired with retrieval, staging, or a second-stage process, or when related alerts show the same paste on this user or host. Close only when the script text, user, and host bind to one authorized simulation or lab workflow with no contradiction. If evidence is mixed or visibility is incomplete, preserve evidence and escalate.
False positive analysis
-
Security-awareness, phishing-simulation, red-team, and malware-analysis labs can paste this lure into PowerShell. Confirm one workflow: the
powershell.file.script_block_textvalue, the expected parent process, and a boundeduser.id/host.id, with no retrieval or second stage outside the exercise. -
Before an exception, require the same script fragment,
user.id, andhost.idacross prior alerts from this rule. Avoid exceptions on the lure phrases,powershell.exe, oruser.namealone.
Response and remediation
-
If confirmed benign, reverse temporary containment and record the script text, parent process,
user.id, andhost.idthat proved the workflow. Create an exception only when that exact workflow recurs. -
If suspicious but unconfirmed, export the script block events, the reconstructed script,
powershell.file.script_block_id, and any child process, file, and destination evidence before cleanup. Apply reversible controls first, such as temporary destination blocks, a browser-session reset, or heightened monitoring. Isolate the host when retrieval or second-stage execution makes continued connectivity risky. - If confirmed malicious, isolate the host, then terminate the PowerShell instance and suspicious descendants after recording identifiers. Remove staged archives, scripts, and payloads, and block confirmed domains, IPs, hashes, or URLs. Reset credentials only when the investigation shows account misuse.
- Post-incident hardening: keep PowerShell script block logging enabled, warn users that a real Cloudflare check never asks them to paste a command into a terminal, and record the lure wording and paste-run chain in the case notes.
Setup
editSetup
PowerShell Script Block Logging must be enabled to generate the events used by this rule (e.g., 4104). Setup instructions: https://ela.st/powershell-logging-setup
Rule query
edithost.os.type:windows and event.category:process and
event.provider:("Microsoft-Windows-PowerShell" or "PowerShellCore") and
event.action:"Execute a Remote Command" and
powershell.file.script_block_text:(
("Clear-Host" or "Write-Host" or "Write-Output" or "Write-Warning" or "cls;" or echo or WriteLine) and
("Cloudflare ID:" or "Cloudflare Services respond" or "Cloudflare verification" or "I am not a robot" or "I'm not a robot")
)
Framework: MITRE ATT&CKTM
-
Tactic:
- Name: Execution
- ID: TA0002
- Reference URL: https://attack.mitre.org/tactics/TA0002/
-
Technique:
- Name: Command and Scripting Interpreter
- ID: T1059
- Reference URL: https://attack.mitre.org/techniques/T1059/
-
Sub-technique:
- Name: PowerShell
- ID: T1059.001
- Reference URL: https://attack.mitre.org/techniques/T1059/001/
-
Technique:
- Name: User Execution
- ID: T1204
- Reference URL: https://attack.mitre.org/techniques/T1204/
-
Sub-technique:
- Name: Malicious Copy and Paste
- ID: T1204.004
- Reference URL: https://attack.mitre.org/techniques/T1204/004/
-
Tactic:
- Name: Initial Access
- ID: TA0001
- Reference URL: https://attack.mitre.org/tactics/TA0001/
-
Technique:
- Name: Drive-by Compromise
- ID: T1189
- Reference URL: https://attack.mitre.org/techniques/T1189/