Netskope Threat Labs

PsDownload

ATP Sandbox Adv. Heuristics

This generic detection identifies PowerShell scripts that download and execute additional malware payloads from remote servers.

First seen
March 2022
Last seen
September 2026
Psdownload
Alert Name
ByteCode-MSIL.Downloader.PsDownload
ByteCode-MSIL.Spyware.PsDownload
ByteCode-MSIL.Trojan.Psdownload
ByteCode-MSIL.Trojan.PsDownload
Email-MIME.Downloader.PsDownload
Win32.Downloader.PsDownload
Win32.Trojan.Psdownload
Win32.Trojan.PsDownload
Win64.Downloader.PsDownload
Win64.Trojan.PsDownload