8c88e73633c2d33ec35b35036e2a1c27b91c5b9aef3596b499f8bea3d2002806unclassified-autoit-compiled: 8c88e736 — New_Order_List_Nov._2024.exe, overlay script placement
Executive Summary
AutoItSC v3.3.8.1 single-file PE32 (New_Order_List_Nov._2024.exe) with a procurement-themed social-engineering lure. Script is stored in the file overlay (not .rsrc) — the twelfth confirmed sibling in the cluster with this placement, which evades resource-only extraction tools such as autoit-ripper. The overlay carries a 16-byte prefix before the AU3!EA06 header, suggesting a possible additional encryption layer or file-inclusion artefact. Static-only analysis; no plaintext C2, payload filenames, or shellcode strings recovered.^[file.txt] ^[pefile.txt] ^[exiftool.json]
What It Is
| Field | Value |
|---|---|
| SHA-256 | 8c88e73633c2d33ec35b35036e2a1c27b91c5b9aef3596b499f8bea3d2002806 |
| Filename | New_Order_List_Nov._2024.exe |
| File type | PE32 executable (GUI) Intel 80386, 4 sections ^[file.txt] |
| Size | 944,869 bytes (923 KB) ^[triage.json] |
| Linker | MSVC 10.0 (VS 2010) ^[pefile.txt:46] |
| PE timestamp | Sun Jan 29 21:32:28 2012 UTC — fabricated ^[pefile.txt:34] ^[rabin2-info.txt:11] |
| AutoIt version | v3.3.8.1 ^[exiftool.json:38] ^[strings.txt:360] |
| VS_VERSIONINFO | Empty (FileDescription blank, CompanyName absent) ^[exiftool.json:36] ^[pefile.txt:242] |
| LangID | British English (080904B0) ^[exiftool.json:34] ^[pefile.txt:240] |
| Signing | Unsigned ^[rabin2-info.txt:27] |
| Entropy (overlay) | ~7.999 (high-entropy encrypted script) |
| YARA | PE_File_Generic, Suspicious_Wininet_Imports ^[yara.txt] |
How It Works
The binary is a standard AutoItSC single-file PE32: the AutoIt v3 interpreter runtime is statically linked as a C++ PE, and the compiled script bytecode is appended after the last PE section. The overlay begins at raw offset 0x99200 (after .rsrc ends at 0x991FF). ^[binwalk.txt] ^[pefile.txt:139-156]
Unlike the majority of cluster siblings that store the script in .rsrc RT_RCDATA, this sample places it in the file overlay. The overlay starts with a 16-byte prefix (a3 48 4b be 98 6c 4a a9 99 4c 53 0a 86 d6 48 7d) before the AU3!EA06 header at raw offset 0x99210. This prefix is identical to the one observed in sibling e08d5bcef (RFQ_3001 FRP/GRP tank lure). It may be an additional encryption layer, a file-inclusion artefact from the AutoItSC compiler, or a build-environment watermark. ^[strings.txt] ^[binwalk.txt]
The script surface is opaque: no plaintext C2 URLs, payload filenames, or shellcode strings are recoverable without decompilation. The AutoIt runtime import table is fully populated, giving the script access to WinInet, WinSock, ADVAPI32, GDI, PSAPI, and ICMP APIs. ^[pefile.txt:257-500]
Decompiled Behavior
No Ghidra decompilation performed. The binary is an AutoItSC interpreter stub; threat logic lives in the encrypted compiled script. Static reverse engineering of the interpreter itself yields no family-specific behavior. Capa flags the AutoIt file limitation and declines further analysis. ^[capa.txt]
C2 Infrastructure
No C2 indicators recovered statically. The script is encrypted and stored in the overlay. The AutoIt runtime imports WinInet and WinSock, confirming network capability, but no hardcoded endpoints are visible. ^[strings.txt:531-571] ^[pefile.txt:355-369]
Interesting Tidbits
- Overlay placement: Twelfth confirmed sibling in the cluster with script in overlay rather than
.rsrc. This placement breaksautoit-ripperand other resource-only extraction pipelines. ^[techniques/autoit-overlay-script-placement.md] - 16-byte prefix: Same prefix (
a3484bbe986c4aa9994c530a86d6487d) as siblinge08d5bcef, suggesting shared build tooling or packer. ^[binwalk.txt] - Filename theme: "New_Order_List_Nov._2024.exe" — procurement/purchase-order lure with month/year suffix, targeting finance/procurement workflows during November 2024.
- Icon suite: Four icons in
.rsrc(ResType 3, IDs 1–4) — typical for this cluster. ^[pefile.txt] - PCRE runtime: Full PCRE regex error-message table present in strings, confirming the AutoItSC v3.3.8.1 runtime. ^[strings.txt:449-516]
- No UPX: Plain PE32 (non-UPX), unlike siblings
798fa958and6cc26f7cthat use UPX transport.
Deployable Signatures
YARA
rule AutoItSC_Overlay_Script_Prefix
{
meta:
description = "AutoItSC single-file PE32 with encrypted script in overlay and 16-byte prefix"
author = "PacketPursuit"
date = "2026-07-23"
family = "unclassified-autoit-compiled"
strings:
$au3_header = "AU3!EA06"
$prefix = { a3 48 4b be 98 6c 4a a9 99 4c 53 0a 86 d6 48 7d }
$mz = "MZ"
condition:
$mz at 0 and
$au3_header and
$prefix in (0x60000..0xA0000) and
pe.number_of_sections == 4 and
pe.imports("WININET.dll")
}
Behavioral fingerprint
This binary is an AutoItSC single-file PE32 with a fabricated Jan 2012 PE timestamp, empty VS_VERSIONINFO, British English LangID, and a high-entropy encrypted script stored in the file overlay rather than .rsrc RT_RCDATA. It loads the full AutoIt v3 runtime (WSOCK32, WININET, ADVAPI32, GDI32, PSAPI, ICMP, USERENV, MPR, COMCTL32, WINMM, VERSION, COMDLG32). The overlay begins with a 16-byte prefix (a3484bbe986c4aa9994c530a86d6487d) before the AU3!EA06 script header. No plaintext C2 strings are present; network behavior is runtime-resolved by the compiled script.
IOC list
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 8c88e73633c2d33ec35b35036e2a1c27b91c5b9aef3596b499f8bea3d2002806 |
Hash |
| Filename | New_Order_List_Nov._2024.exe |
Filename |
| PE timestamp | 0x4F25BAEC (2012-01-29 21:32:28 UTC) |
Timestamp |
| AutoIt version | 3.3.8.1 |
Version |
| Overlay prefix | a3484bbe986c4aa9994c530a86d6487d |
Bytes |
| LangID | 080904B0 (British English) |
Metadata |
Detection Signatures
- MITRE ATT&CK: T1059.005 (AutoIt script execution) via the compiled interpreter.
- Network: T1071.001 (Web Protocols) / T1095 (Non-Application Layer Protocol) inferred from WinInet/WinSock imports.
- Persistence: T1547.001 (Registry Run) possible via ADVAPI32
RegSetValueExWimported by the runtime. - Discovery: T1083, T1057, T1012 inferred from standard AutoItSC API surface.
- Collection: T1113, T1115, T1056.001 possible via GDI32 and USER32 imports.
References
[unclassified-autoit-compiled](/intel/families/unclassified-autoit-compiled.html)— cluster entity page[autoit-compiled-script-dropper](/intel/concepts/autoit-compiled-script-dropper.html)— concept page[autoit-overlay-script-placement](/intel/techniques/autoit-overlay-script-placement.html)— technique page
Provenance
file.txt—fileutility outputpefile.txt— pefile Python library dumpexiftool.json— ExifTool metadata extractionstrings.txt— GNU strings outputrabin2-info.txt— radare2 binary header summarybinwalk.txt— binwalk embedded artefact scancapa.txt— Mandiant capa capability detection (AutoIt file limitation)yara.txt— YARA rule matches