Skip to content

Hide Navigation Hide TOC

HELAUTO (7c05c816-481f-499e-9545-d48b635dc2eb)

This family of malware is designed to operate as a service and provides remote command execution and file transfer capabilities to a fixed IP address or domain name. All communication with the C2 server happens over port 443 using SSL. This family can be installed as a service DLL. Some variants allow for uninstallation.

Cluster A Galaxy A Cluster B Galaxy B Level
Helauto (9af26655-cfba-4e02-bd10-ad1a494e0b5f) Malpedia HELAUTO (7c05c816-481f-499e-9545-d48b635dc2eb) Tool 1