AutoIT Payload Injector , (Tue, Jul 28th)
ID: 46d05d8b-12bb-52f4-96a2-a921316bc053
STIX ID: report--46d05d8b-12bb-52f4-96a2-a921316bc053
Feed Name: SANS ISC Diary
An email campaign delivers a RAR attachment containing a VBS that decodes a Base64 payload and uses PowerShell to drop an AutoIT interpreter and associated scripts; those AutoIT scripts XOR-decode embedded files, persist via a Run registry key, launch charmap.exe, and inject XOR-decoded shellcode that installs VIPKeylogger which contacts cphost17.qhoster.net. The report includes SHA256 hashes, code snippets, API/TTP mappings (OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread), and links to related analyses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
