DarkGate - Autoit3.EXE File Creation By Uncommon Process
Description
Detects the usage of curl.exe, KeyScramblerLogon, or other non-standard/suspicious processes used to create Autoit3.exe. This activity has been associated with DarkGate malware, which uses Autoit3.exe to execute shellcode that performs process injection and connects to the DarkGate command-and-control server. Curl, KeyScramblerLogon, and these other processes consitute non-standard and suspicious ways to retrieve the Autoit3 executable.
Query · sigma
selection: Image|endswith: - \Autoit3.exe - \curl.exe - \ExtExport.exe - \KeyScramblerLogon.exe - \wmprph.exe TargetFilename|endswith: \Autoit3.exe condition: selection
Known false positives
- Unknown