• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    PowerShell AES-decrypt and reflective .NET assembly load (LausivLoader)

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 15 days ago•0•0•3

    Detects the use of PowerShell command lines containing both 'AesManaged' for decryption and '[System.Reflection.Assembly]::Load' for reflective loading of a .NET assembly in memory. This pattern is consistent with the execution stage of malware such as LausivLoader, which stage encrypted payloads and load them directly into the process memory to evade disk-based detection.

    YARA-L

    Tags

    T1059.001 - PowerShellT1620 - Reflective Code LoadingTA0002 - ExecutionTA0005 - StealthPowershell Script ExecutionScript ExecutionProcess CreationWindowsWindows Eventlog Powershell

    Found in

    • LausivLoader Analysis: Multi-Stage Infection via Environment VariablesLast updated 16 days ago
    • LausivLoader Analysis: Multi-Stage Infection via Environment VariablesLast updated 16 days ago
    • LausivLoader Analysis: Multi-Stage Infection via Environment VariablesLast updated 16 days ago
    • LausivLoader Analysis: Multi-Stage Infection via Environment VariablesLast updated 16 days ago
    • LausivLoader Analysis: Multi-Stage Infection via Environment VariablesLast updated 16 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?