Payload Delivery
Description
ZLoader was delivered in a campaign in summer 2021 via malvertising. This campaign was tweeted about by @MsftSecIntel on twitter.
Query · kql
DeviceNetworkEvents
| where InitiatingProcessFileName =~ 'powershell.exe'
and InitiatingProcessCommandLine has('Invoke-WebRequest') and InitiatingProcessCommandLine endswith '-OutFile tim.EXE'