Contenu disponible en langue originale
class="post-article">

AutoItRAT

AutoIt3 compiled RAT (LightToolV9). GetAsyncKeyState keylogger. BitBlt+GetDesktopWindow screen capture. VirtualAllocEx+WriteProcessMemory process injection. InternetOpenW+HttpSendRequestW HTTP C2. TCPCLOSESOCKET TCP. AdjustTokenPrivileges privilege escalation. BITXOR XOR obfuscation. Spoofed PE timestamp.

Profil de menace
Type RAT
Langage de programmationAutoIt
Protocole C2HTTP/TCP
Première détection2022
Cibles Küresel
Objectif / Capacités
  • Remote Access/Keylogger/Screenshot/Process Injection
Aucun serveur C2 n'a encore été identifié pour cette famille.

Rapports de recherche (1)

Yüksek

AutoItRAT LightToolV9 -- GetAsyncKeyState Klavye Keylogger, BitBlt GetDesktopWindow Ekran Görüntüsü, VirtualAllocEx WriteProcessMemory Proses Enjeksiyonu, InternetOpenW HttpSendRequestW HTTP C2, AdjustTokenPrivileges Hak Yükseltme, BITXOR XOR Obfuskasyon | Yüksek

AutoItRAT LightToolV9.exe 962KB. GetAsyncKeyState klavye keylogger. BitBlt GetDesktopWindow ekran goruntüsü. VirtualAllocEx WriteProcessMemory proses enjeksiyonu. InternetOpenW HttpSendRequestW HTTP C2. AdjustTokenPrivileges hak yukseltme. BITXOR XOR obfuskasyon.

Lire le rapport →