Command Line Execution with Suspicious URL and AppData Strings — Detection Rule

Detects a suspicious command line execution that includes an URL and AppData string in the command line parameters as used by several droppers (js/vbs > powershell)

Read the full analysis on IntelFusions