Commonly abused AutoIT script connects to an external domain
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Exfiltration (TA0010), Execution (TA0002)
ATT&CK Technique
Command and Scripting Interpreter: AutoHotKey & AutoIT (T1059.010), Automated Exfiltration (T1020)
Severity
Medium
Description
AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context.
Attacker's Goals
Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines.
Investigative actions
AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context.
Identify the process contacting the remote domain and determine whether the traffic is malicious.
Was this helpful?
