HELAUTO - 'svchostdll.dll does not exist'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

HELAUTO is an HTTPS-based backdoor that communicates over TCP port 443. All communication with the remote host is encrypted using SSL. The
first connection the malware makes to the remote host is used as a beacon in order to notify that the victim host is ready to accept a
command. It sends the request 'Hello.I am here!'. The server responds with a Web page containing a command embedded within the <head> tag
of its HTML code.
ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.57