Suspicious PowerShell Out-of-Band Request to Interactsh Domain

PremiumReviewedSigma · High · v1
Category
process_creation
Author
HuntRule
Published
2026-09-29
Updated
2026-09-29

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects PowerShell issuing a web request to Interactsh out-of-band domains such as oastify.com or oast.fun, used by attackers to confirm CVE-2025-30406 exploitation against Gladinet CentreStack as reported by Huntress. Adversaries trigger DNS or HTTP callbacks to validate code execution before deploying payloads. Outbound callbacks to out-of-band interaction services from PowerShell strongly indicate exploitation or reconnaissance.

Related detections9 linkedT1059.001 — drag to rearrange
Malicious IIS Worker Process Spawning PowerShell via Gladinet CentreStack Exploit
Exchange Worker Process Spawning Command Shell via OWASSRF
Suspicious SharePoint Worker Process Spawning Command Interpreter via ToolShell
Malicious ActiveMQ Exploitation Java Spawning PowerShell Downloader (via process_creation)
Suspicious Cleo Autorun Health Check File Drop (via file_event)
Obfuscated IIS Worker Spawning Encoded PowerShell after SharePoint ToolShell (via process_creation)
Malicious WSUS Service Spawning Command Shell via Remote Code Execution
Malicious PowerShell Spawned by IIS Worker Process via OWASSRF Exchange Exploitation (via process_creation)
Suspicious Child Process Spawned From Java Following Web Exploitation
Suspicious PowerShell Out-of-Band Request to Interactsh Domain
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.