CRPx0 encoded PowerShell stages Stage2 DLL as WindowsUpdate.log
Detects the execution of base64 encoded PowerShell commands used by CRPx0 to stage a DLL payload, specifically saving it as 'WindowsUpdate.log' followed by the execution of that payload using rundll32.exe.
YARA-L

