LIGHTBOLT - 'all.jpg does not exist'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

LIGHTBOLT is a utility with the ability to perform HTTP GET requests for a list of user-specified URLs. The responses of the HTTP requests
are then saved as MHTML files, which are added to encrypted RAR files. This is very similar in functionality to the LIGHTDART malware
family, however LIGHTBOLT has integrated additional functionality in the form of the ability to use software certificates for
authentication. By integrating stolen software certificates into LIGHTBOLT, an attacker can access web pages that aren't readily available
on the Internet.
ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.143