logo

AutoIT Payload Injector , (Tue, Jul 28th)

ID: 46d05d8b-12bb-52f4-96a2-a921316bc053

STIX ID: report--46d05d8b-12bb-52f4-96a2-a921316bc053

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

...
...

An email campaign delivers a RAR attachment containing a VBS that decodes a Base64 payload and uses PowerShell to drop an AutoIT interpreter and associated scripts; those AutoIT scripts XOR-decode embedded files, persist via a Run registry key, launch charmap.exe, and inject XOR-decoded shellcode that installs VIPKeylogger which contacts cphost17.qhoster.net. The report includes SHA256 hashes, code snippets, API/TTP mappings (OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread), and links to related analyses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.