PowerShell AES-decrypt and reflective .NET assembly load (LausivLoader)
Detects the use of PowerShell command lines containing both 'AesManaged' for decryption and '[System.Reflection.Assembly]::Load' for reflective loading of a .NET assembly in memory. This pattern is consistent with the execution stage of malware such as LausivLoader, which stage encrypted payloads and load them directly into the process memory to evade disk-based detection.
YARA-L

