Warning! Audit Deprecated
Information
HELAUTO is an HTTPS-based backdoor that communicates over TCP port 443. All communication with the remote host is encrypted using SSL. The
first connection the malware makes to the remote host is used as a beacon in order to notify that the victim host is ready to accept a
command. It sends the request 'Hello.I am here!'. The server responds with a Web page containing a command embedded within the <head> tag
of its HTML code.
ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.57