Purely-Powershell Malware.
Only caught by UAC.
Bypasses AV as of 2019.
- Bypass
- Register Alterations
- Persistence
- Event Clears
- Encoding
- Compression
- Splitting
- String formatting
- Runs only on host computer.
- Kills execution within a VM.
- Payload: Stop-computer
- Allows VM execution.
- Includes 3 execution halts for easier reversing.
- More obfuscation, encoding, string formats.
- Payload: Stop-computer