AutoIT3 Compiled Scripts Dropping Shellcodes, (Fri, Dec 5th)
ID: 596d63cf-6063-5ef4-9991-e006a34ace2d
STIX ID: report--596d63cf-6063-5ef4-9991-e006a34ace2d
Feed Name: SANS ISC Diary
Threat Score
The report analyzes an AutoIt3 malware sample that leverages the FileInstall feature to embed and drop payload files, decodes obfuscated strings, writes a shellcode file to %TEMP%, allocates executable memory and invokes the shellcode via CallWindowProc; two SHA256s are provided (one associated with a Phantom stealer) and the author warns of an ongoing wave of similar samples and to monitor FileInstall usage in AutoIt scripts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
