APT36 fake Edge updater task runs encoded PowerShell to indiatodays[.]org
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
Microsoft Sentinel (KQL)

