AutoUpdate.exe fetching remote update manifest from malicious C2
This rule detects a suspicious sequence of events where a process with a name resembling an updater (AutoUpdate.exe or au.exe) accesses a specific remote configuration file from a herokuapp.com URL, followed by the creation or modification of specific application binaries (e.g., InstaTime.exe, ffmpegsumo.dll). This pattern is indicative of a supply chain compromise or an automated software update hijacking where malicious binaries are staged to replace legitimate application components.
Microsoft Sentinel (KQL)

