HELAUTO (7c05c816-481f-499e-9545-d48b635dc2eb)
This family of malware is designed to operate as a service and provides remote command execution and file transfer capabilities to a fixed IP address or domain name. All communication with the C2 server happens over port 443 using SSL. This family can be installed as a service DLL. Some variants allow for uninstallation.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Helauto (9af26655-cfba-4e02-bd10-ad1a494e0b5f) | Malpedia | HELAUTO (7c05c816-481f-499e-9545-d48b635dc2eb) | Tool | 1 |