Analytics BIOC
Medium
✕
Commonly abused AutoIT script connects to an external domain
AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Exfiltration (TA0010) Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: AutoHotKey & AutoIT (T1059.010) Automated Exfiltration (T1020)
Attacker's goals:
Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines.
Investigative actions:
AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. Identify the process contacting the remote domain and determine whether the traffic is malicious.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day