PowerShell AES-decrypt + GZip + Reflective .NET Assembly Load
Detects the execution of PowerShell scripts that utilize a multi-stage deobfuscation and loading technique. The script decrypts a staged payload using AesManaged (with specific hardcoded byte constants), decompresses the result via GZipStream, and uses [System.Reflection.Assembly]::Load to reflectively execute the resulting .NET assembly in memory. This pattern is characteristic of advanced malware loader chains, such as those used by the 'LausivLoader'.
YARA-L

