BIOC Low

Commonly abused AutoIT script connects to a remote host

AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context.

Module:
Platform Analytics
Agent event type:
Network
Category:
Exfiltration
Status:
Enabled
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Automated Exfiltration (T1020)
Indicator:

Network action type = outgoing , failed Process initiator signature = Signed , Weak Hash AND initiator signer = Autoit* AND Autoit* Host host os = windows

Preventable: yes