LIGHTDART - '1.rar does not exist'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

LIGHTDART is a tool used to access a pre-configured Web page that hosts an interface to query a database or data set. The tool then
downloads the results of a query against that Web page to an encrypted RAR file. This RAR file (1.rar) is renamed and uploaded to an
attacker controlled FTP server, or uploaded via an HTTP POST with a .jpg extension. The malware will execute this search once a day. The
target Web page usually contains information useful to the attacker, which is updated on a regular basis.
ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.5