Malware is a click-fraud malware famous from the unconventional tricks used for persistence. It hides malicious modules in PowerShell scripts as well as in registry keys to make detection and analysis difficult. In this post we will take a deep dive into the techniques used by its latest samples to see all the elements and how they cooperate together. The malware is signed by a valid Comodo certificate (it got revoked later) The payload is loaded into an allocated, continuous area in the memory (without dividing content into sections)”]
Source: https://blog.malwarebytes.com/threat-analysis/2016/07/untangling-kovter/

