Windows Process Creation: Renamed AutoIt2/AutoIt3 Execution via AutoIt3ExecuteScript
Alerts on suspicious renamed AutoIt2/AutoIt3 execution based on command-line parameters plus known hashes and original file names.
FreeUnreviewedSigmahighv1
windows-process-creation-renamed-autoit2-autoit3-execution-via-autoit3executescr-f4264e47
title: "Windows Process Creation: Renamed AutoIt2/AutoIt3 Execution via AutoIt3ExecuteScript"
id: a7f0d415-8b45-41bb-b0a6-7d1f5de34578
status: test
description: This rule flags Windows process creation events where the command line includes AutoIt execution parameters (such as /AutoIt3ExecuteScript and /ErrorStdOut) and the process relates to AutoIt executables by hash and original file name. Attackers may rename AutoIt binaries to blend in, then use the scripting engine to run payloads or automate malicious actions. The detection relies on process command-line content, imphash values, and OriginalFileName fields, while filtering out executions of expected, known AutoIt file names.
references:
- https://twitter.com/malmoeb/status/1665463817130725378?s=12&t=C0_T_re0wRP_NfKa27Xw9w
- https://www.autoitscript.com/site/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_renamed_autoit.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2023-06-04
modified: 2024-11-23
tags:
- attack.stealth
- attack.t1027
logsource:
category: process_creation
product: windows
detection:
selection_1:
CommandLine|contains:
- " /AutoIt3ExecuteScript"
- " /ErrorStdOut"
selection_2:
Hashes|contains:
- IMPHASH=FDC554B3A8683918D731685855683DDF
- IMPHASH=CD30A61B60B3D60CECDB034C8C83C290
- IMPHASH=F8A00C72F2D667D2EDBB234D0C0AE000
selection_3:
OriginalFileName:
- AutoIt3.exe
- AutoIt2.exe
- AutoIt.exe
filter_main_legit_name:
Image|endswith:
- \AutoIt.exe
- \AutoIt2.exe
- \AutoIt3_x64.exe
- \AutoIt3.exe
condition: 1 of selection_* and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: f4264e47-f522-4c38-a420-04525d5b880f
type: derived
What it detects
This rule flags Windows process creation events where the command line includes AutoIt execution parameters (such as /AutoIt3ExecuteScript and /ErrorStdOut) and the process relates to AutoIt executables by hash and original file name. Attackers may rename AutoIt binaries to blend in, then use the scripting engine to run payloads or automate malicious actions. The detection relies on process command-line content, imphash values, and OriginalFileName fields, while filtering out executions of expected, known AutoIt file names.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.