typeanalysisfamilyunclassified-autoit-compiledconfidencehighcreated2026-07-25updated2026-07-25malware-familyloaderautoitevasionpec2persistencediscovery
SHA-256: 29d3d47167a90e599940a605dae6fae187d462ec2ab515e3f2b3506af3c28450

unclassified-autoit-compiled: 29d3d471 — Proforma-invoice lure, 309 KB SCRIPT in .rsrc, Nov 2024 build

Executive Summary

Sixtieth confirmed sibling in the unclassified-autoit-compiled AutoItSC single-file PE32 cluster. Distributed as Revised_PI.exe (proforma invoice social-engineering lure). AutoItSC v3.3.8.1 with MSVC 11.0 (VS 2012) linker, genuine Nov 2024 PE timestamp. Script stored in .rsrc RT_RCDATA (309 KB, AU3!EA06 header) — not overlay. Empty VS_VERSIONINFO, British English LangID, 11-icon suite. Standard AutoItSC import surface; no plaintext C2, payload filenames, or shellcode strings recovered. Static-only.

What It Is

Field Value
SHA-256 29d3d47167a90e599940a605dae6fae187d462ec2ab515e3f2b3506af3c28450
Filename Revised_PI.exe ^[triage.json]
File type PE32 executable (GUI) Intel 80386, 5 sections ^[file.txt]
Size 1,175,552 bytes (1.12 MB) ^[triage.json]
Compiler AutoItSC v3.3.8.1 single-file compiler ^[strings.txt:549]
Linker MSVC 11.0 (Visual Studio 2012) ^[pefile.txt:46]
PE timestamp Wed Nov 13 05:15:15 2024 UTC (genuine) ^[pefile.txt:34]
Signed No ^[rabin2-info.txt:30]
PDB None ^[pefile.txt:36]
Script placement .rsrc RT_RCDATA ID SCRIPT (not overlay) ^[pefile.txt:1416]
Script size 316,796 bytes (~309 KB), entropy 7.89 ^[pefile.txt:1439]
Script header AU3!EA06 ^[strings.txt:1317] ^[strings.txt:1856]
VS_VERSIONINFO Empty (FileVersion 0.0.0.0, ProductVersion 0.0.0.0) ^[pefile.txt:237-248]
LangID British English (080904B0) ^[pefile.txt:260] ^[exiftool.json:34]
Icons 9 RT_ICON + 2 RT_GROUP_ICON = 11 total ^[pefile.txt:965-976] ^[pefile.txt:1405-1416]
Overlay No (rabin2 overlay: false) ^[rabin2-info.txt:26]
CAPE Skipped — no Windows guest available ^[dynamic-analysis.md:3]

Cluster attribution: high confidence. Every build artefact matches the unclassified-autoit-compiled fingerprint: AutoItSC v3.3.8.1 runtime, empty VS_VERSIONINFO, British English LangID, standard import surface including WSOCK32/WININET/ADVAPI32/GDI32/PSAPI/IPHLPAPI/USERENV/MPR/COMCTL32/WINMM/VERSION/UxTheme, and full PCRE regex library strings. The proforma-invoice filename (Revised_PI.exe) is a new lure theme for this cluster — previously observed themes include purchase-order, RFQ, DHL airway-bill, SOA, salary, payment, and logistics-tracking.

How It Works

The binary is a single-file AutoIt v3 compiled executable. On launch, the embedded AutoIt interpreter reads the encrypted SCRIPT resource from .rsrc, decrypts it in-memory, and executes the bytecode. The actual threat logic lives entirely inside the compiled script; the PE is just the runtime carrier. ^[capa.txt:1-24]

Because the script is encrypted/compiled, static analysis of the PE surface reveals only the AutoIt runtime imports and the PCRE regex library strings — no payload filenames, no C2 URLs, no shellcode indicators, and no persistence commands. This is by design: AutoItSC provides natural static obfuscation. The cluster's inner payloads (observed in decompiled siblings) typically perform one or more of: dual-file drop to %TEMP%, Caesar/hex string obfuscation, x86 shellcode allocation via VirtualAlloc RWX + DllCallAddress or CallWindowProc, XOR-decryption of a second-stage PE, and process hollowing into svchost.exe or .NET RegSvcs.exe.

This particular sibling (29d3d471) has not been decompiled; the script is encrypted and no plaintext payload strings were recovered. It is a clean-cluster sibling with no unique per-sample artefacts beyond the filename lure and the Nov 2024 build timestamp.

Decompiled Behavior

Ghidra / radare2 decompilation of the PE surface is uninformative — the .text section is the AutoItSC runtime (~570 KB), not the threat logic. The entry point (0x25F74) is the standard AutoIt interpreter bootstrap. No notable functions beyond the runtime's WinMain → AutoItWinMain → script-loader chain. Capa correctly flags the AutoIt limitation and aborts deep analysis. ^[capa.txt:1-24]

No obfuscation, anti-debug, or VM-detection logic in the PE itself; evasion is delegated to the compiled script layer.

C2 Infrastructure

No C2 indicators recovered from static analysis. The script is encrypted; no plaintext IPs, domains, URLs, mutexes, named pipes, or registry keys were found. Historical siblings in this cluster have shown: WebDAV payload fetch, HTTP downloader stubs, raw TCP sockets, and SMTP exfil — but those were visible only after script decompilation. For this sample, C2 is opaque without dynamic execution or script decryption. ^[strings.txt:1-2456]

Interesting Tidbits

  • Proforma-invoice lure theme: Revised_PI.exe is the first "proforma invoice" masquerade in this cluster, expanding the social-engineering target set beyond purchase-order, RFQ, and DHL logistics lures. This suggests the builder operator customizes filenames per campaign or client vertical. ^[triage.json]
  • Nov 2024 build timestamp: The PE timestamp (Wed Nov 13 05:15:15 2024 UTC) is genuine, not the fabricated Jan 2012 timestamp seen in ~40% of cluster siblings. This places the build two days before the db9d07fd sibling (Nov 15 2024) and one month before dca60b6b (Dec 2024). ^[pefile.txt:34]
  • MSVC 11.0 (VS 2012) linker: Unusual for this cluster, which skews heavily toward MSVC 14.x (VS 2017–2019). The older linker suggests this build used an older AutoItSC toolchain or a builder VM with legacy Visual Studio. ^[pefile.txt:46]
  • 11-icon suite: Richer than the cluster average (typically 4 icons). The additional icons may improve Explorer thumbnail credibility for the proforma-invoice lure. ^[pefile.txt:965-976]
  • 309 KB script size: Smaller than the cluster average (~400 KB median, 932 KB max from f0059bee). A smaller script may indicate a leaner payload or a newer builder revision with stripped runtime. ^[pefile.txt:1439]
  • No UPX packing: Plain PE32, unlike transport-layer siblings 798fa958 and 68e48a8c which are UPX-wrapped duplicates of inner payloads. ^[triage.json]

How To Mess With It (Homelab Replication)

  1. Install AutoIt v3.3.8.1 or later from https://www.autoitscript.com/site/autoit/downloads/
  2. Write a malicious AutoIt script (e.g., dropper, downloader, keylogger)
  3. Compile with Aut2Exe.exe (right-click script → Compile Script) or AutoItSC.exe /in script.au3 /out dropper.exe
  4. Verify the output PE has:
    • AU3!EA06 header in .rsrc RT_RCDATA or file overlay
    • Empty VS_VERSIONINFO
    • British English LangID (080904B0)
    • Standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, GDI, PSAPI, etc.)
  5. Run capa dropper.exe — should flag "compiled with AutoIt" and abort with the same limitation warning as this sample
  6. Observe that static string extraction yields only PCRE regex error messages and runtime imports; actual C2/payload strings remain inside the encrypted script

What you'll learn: AutoItSC provides "free" static obfuscation — the PE surface is just the interpreter, and the threat logic is encrypted bytecode. This is why the cluster has 60+ siblings with minimal static differentiation.

Deployable Signatures

YARA rule

rule AutoItSC_SingleFile_PE32_Generic {
    meta:
        description = "Generic AutoItSC single-file PE32 — encrypted script in .rsrc or overlay"
        author = "PacketPursuit SOC"
        date = "2026-07-25"
        sha256 = "29d3d47167a90e599940a605dae6fae187d462ec2ab515e3f2b3506af3c28450"
    strings:
        $au3_header = "AU3!EA06"
        $autoit_runtime = "This is a third-party compiled AutoIt script."
        $pcre_utf = "this version of PCRE is compiled without UTF support"
        $pcre_unicode = "PCRE does not support \\L, \\l, \\N{name}, \\U, or \\u"
    condition:
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x4550 and
        ($au3_header or $autoit_runtime) and
        any of ($pcre_*)
}

Behavioral hunt query (KQL / Microsoft Defender for Endpoint)

DeviceProcessEvents
| where FileName endswith ".exe"
| where ProcessCommandLine contains "Revised_PI" or ProcessCommandLine contains "Revised_PI.exe"
| summarize count() by DeviceName, AccountName, InitiatingProcessFileName

IOC list

Indicator Type Note
29d3d47167a90e599940a605dae6fae187d462ec2ab515e3f2b3506af3c28450 SHA-256 Sample hash
Revised_PI.exe Filename Proforma-invoice social-engineering lure
AU3!EA06 String AutoItSC encrypted script header
080904B0 LangID British English (cluster fingerprint)
Empty VS_VERSIONINFO Version info FileVersion 0.0.0.0, ProductVersion 0.0.0.0

Behavioral fingerprint

This binary is a PE32 GUI executable compiled with AutoItSC v3.3.8.1. It contains an encrypted compiled script (~309 KB) in .rsrc RT_RCDATA or the file overlay, prefixed with AU3!EA06. The PE imports WSOCK32, WININET, ADVAPI32, GDI32, PSAPI, IPHLPAPI, USERENV, MPR, COMCTL32, WINMM, VERSION, and UxTheme — the standard AutoIt runtime surface. No C2 strings, payload filenames, or shellcode indicators are visible in the PE strings. On execution, the AutoIt interpreter decrypts and executes the script bytecode in-memory; actual malicious behavior (downloading, dropping, injecting, exfiltrating) is script-side and opaque to static PE analysis.

Detection Signatures

ATT&CK Technique Evidence Provenance
T1059.005 (Command and Scripting Interpreter: Visual Basic / AutoIt) Compiled AutoIt script execution ^[capa.txt] ^[strings.txt:549]
T1071.001 (Web Protocols) WININET.dll imports (HTTP/FTP client APIs) ^[pefile.txt:372-384]
T1095 (Non-Application Layer Protocol) WSOCK32.dll imports (raw socket APIs) ^[pefile.txt:284-306]
T1547.001 (Registry Run) ADVAPI32.dll RegSetValueExW import ^[pefile.txt:838]
T1053.005 (Scheduled Task) AutoIt Run / COM APIs available via runtime Inferred from import surface
T1083 (File and Directory Discovery) FindFirstFileW, FindNextFileW imports ^[pefile.txt:475-479]
T1057 (Process Discovery) CreateToolhelp32Snapshot, Process32FirstW, Process32NextW ^[pefile.txt:470-472]
T1012 (Query Registry) RegOpenKeyExW, RegQueryValueExW imports ^[pefile.txt:841-842]
T1113 (Screen Capture) GDI32.dll imports (screen capture APIs) Inferred from standard AutoItSC surface
T1115 (Clipboard Data) Clipboard APIs available via AutoIt runtime Inferred from standard AutoItSC surface
T1056.001 (Keylogging) GetAsyncKeyState available via AutoIt runtime Inferred from standard AutoItSC surface

References

Provenance

Analysis derived from:

  • file.txt — file-type identification (file v5.44)
  • exiftool.json — PE metadata (ExifTool v12.76)
  • pefile.txt — PE structure, sections, imports, resources, VS_VERSIONINFO (pefile Python library)
  • strings.txt — ASCII/Unicode string extraction (strings v2.42)
  • floss.txt — flare-floss v3.1.1 (failed due to CLI argument mismatch; no decoded strings)
  • capa.txt — Mandiant capa v7.0.0 (AutoIt limitation warning, no capabilities)
  • rabin2-info.txt — radare2 rabin2 v5.9.6 (binary header summary)
  • binwalk.txt — binwalk v2.3.4 (PE + CRC32 table)
  • triage.json — PacketPursuit triage pipeline metadata
  • yara.txt — YARA rules (PE_File_Generic, Suspicious_Wininet_Imports)
  • ssdeep.txt — ssdeep fuzzy hash
  • tlsh.txt — TLSH hash
  • metadata.json — OpenCTI connector metadata
  • dynamic-analysis.md — CAPE sandbox status (skipped, no Windows guest)