DarkGate - Autoit3.EXE Execution Parameters — Detection Rule

Detects execution of the legitimate Autoit3 utility from a suspicious parent process. AutoIt3.exe is used within the DarkGate infection chain to execute shellcode that performs process injection and connects to the DarkGate command-and-control server.

Read the full analysis on IntelFusions