| Word Dropper | parent_name:winword.exe AND process_name:powershell.exe AND netconn_count:[1 TO *] |
| PowerShell Second Stage | (domain:pastebin.com) and process_name:powershell.exe |
| PowerShell Second Stage | process_name:powershell.exe AND filemod:ProgramData\*.exe |
| PowerShell Downgrade | modload:windows\assembly\nativeimages_v*_32\*\*\system.management.automation.ni.dll and parent_name:powershell.exe AND netconn_count:[1 TO *] -cmdline:windows\\ccmcache* |
| PowerShell Downgrade | modload:windows\assembly\nativeimages_v*_32\*\*\system.management.automation.ni.dll and parent_name:powershell.exe AND childproc_name:csc.exe and -cmdline:windows\\ccmcache* |