Detects execution of the POWERHOLD script seen used by FIN7 as reported by WithSecureLabs
Read the full analysis on IntelFusions