MalwareBazaar Database
This page shows some basic information the YARA rule PS_XOR_Reflection_Loader_StatusCode including corresponding malware samples.
Database Entry
| YARA Rule: | PS_XOR_Reflection_Loader_StatusCode |
|---|---|
| Author: | Marjoriefort |
| Description: | Obfuscated PowerShell .NET loader (builder statusCode family): XOR byte decode + reflection + HMAC-32 + scriptblock/IEX exec |
| Firstseen: | 2026-09-25 22:45:36 UTC |
| Lastseen: | never |
| Sightings: | 1 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
| Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
|---|