PowerShell AES-CBC Decrypt and Gzip-Decompress .NET DLL In Memory
Detects the use of PowerShell commands that perform decryption (AES-256-CBC) and decompression (Gzip) of data, followed by the reflective loading of a .NET assembly into memory using [Reflection.Assembly]::Load. This behavior is indicative of fileless malware execution where a payload is hidden in an obfuscated or compressed format and unpacked at runtime.
Sigma

