typeanalysisfamilyunclassified-autoit-compiledconfidencehighcreated2026-07-23updated2026-07-23malware-familyloaderautoitevasionpec2
SHA-256: 8c88e73633c2d33ec35b35036e2a1c27b91c5b9aef3596b499f8bea3d2002806

unclassified-autoit-compiled: 8c88e736 — New_Order_List_Nov._2024.exe, overlay script placement

Executive Summary

AutoItSC v3.3.8.1 single-file PE32 (New_Order_List_Nov._2024.exe) with a procurement-themed social-engineering lure. Script is stored in the file overlay (not .rsrc) — the twelfth confirmed sibling in the cluster with this placement, which evades resource-only extraction tools such as autoit-ripper. The overlay carries a 16-byte prefix before the AU3!EA06 header, suggesting a possible additional encryption layer or file-inclusion artefact. Static-only analysis; no plaintext C2, payload filenames, or shellcode strings recovered.^[file.txt] ^[pefile.txt] ^[exiftool.json]

What It Is

Field Value
SHA-256 8c88e73633c2d33ec35b35036e2a1c27b91c5b9aef3596b499f8bea3d2002806
Filename New_Order_List_Nov._2024.exe
File type PE32 executable (GUI) Intel 80386, 4 sections ^[file.txt]
Size 944,869 bytes (923 KB) ^[triage.json]
Linker MSVC 10.0 (VS 2010) ^[pefile.txt:46]
PE timestamp Sun Jan 29 21:32:28 2012 UTC — fabricated ^[pefile.txt:34] ^[rabin2-info.txt:11]
AutoIt version v3.3.8.1 ^[exiftool.json:38] ^[strings.txt:360]
VS_VERSIONINFO Empty (FileDescription blank, CompanyName absent) ^[exiftool.json:36] ^[pefile.txt:242]
LangID British English (080904B0) ^[exiftool.json:34] ^[pefile.txt:240]
Signing Unsigned ^[rabin2-info.txt:27]
Entropy (overlay) ~7.999 (high-entropy encrypted script)
YARA PE_File_Generic, Suspicious_Wininet_Imports ^[yara.txt]

How It Works

The binary is a standard AutoItSC single-file PE32: the AutoIt v3 interpreter runtime is statically linked as a C++ PE, and the compiled script bytecode is appended after the last PE section. The overlay begins at raw offset 0x99200 (after .rsrc ends at 0x991FF). ^[binwalk.txt] ^[pefile.txt:139-156]

Unlike the majority of cluster siblings that store the script in .rsrc RT_RCDATA, this sample places it in the file overlay. The overlay starts with a 16-byte prefix (a3 48 4b be 98 6c 4a a9 99 4c 53 0a 86 d6 48 7d) before the AU3!EA06 header at raw offset 0x99210. This prefix is identical to the one observed in sibling e08d5bcef (RFQ_3001 FRP/GRP tank lure). It may be an additional encryption layer, a file-inclusion artefact from the AutoItSC compiler, or a build-environment watermark. ^[strings.txt] ^[binwalk.txt]

The script surface is opaque: no plaintext C2 URLs, payload filenames, or shellcode strings are recoverable without decompilation. The AutoIt runtime import table is fully populated, giving the script access to WinInet, WinSock, ADVAPI32, GDI, PSAPI, and ICMP APIs. ^[pefile.txt:257-500]

Decompiled Behavior

No Ghidra decompilation performed. The binary is an AutoItSC interpreter stub; threat logic lives in the encrypted compiled script. Static reverse engineering of the interpreter itself yields no family-specific behavior. Capa flags the AutoIt file limitation and declines further analysis. ^[capa.txt]

C2 Infrastructure

No C2 indicators recovered statically. The script is encrypted and stored in the overlay. The AutoIt runtime imports WinInet and WinSock, confirming network capability, but no hardcoded endpoints are visible. ^[strings.txt:531-571] ^[pefile.txt:355-369]

Interesting Tidbits

  • Overlay placement: Twelfth confirmed sibling in the cluster with script in overlay rather than .rsrc. This placement breaks autoit-ripper and other resource-only extraction pipelines. ^[techniques/autoit-overlay-script-placement.md]
  • 16-byte prefix: Same prefix (a3484bbe986c4aa9994c530a86d6487d) as sibling e08d5bcef, suggesting shared build tooling or packer. ^[binwalk.txt]
  • Filename theme: "New_Order_List_Nov._2024.exe" — procurement/purchase-order lure with month/year suffix, targeting finance/procurement workflows during November 2024.
  • Icon suite: Four icons in .rsrc (ResType 3, IDs 1–4) — typical for this cluster. ^[pefile.txt]
  • PCRE runtime: Full PCRE regex error-message table present in strings, confirming the AutoItSC v3.3.8.1 runtime. ^[strings.txt:449-516]
  • No UPX: Plain PE32 (non-UPX), unlike siblings 798fa958 and 6cc26f7c that use UPX transport.

Deployable Signatures

YARA

rule AutoItSC_Overlay_Script_Prefix
{
    meta:
        description = "AutoItSC single-file PE32 with encrypted script in overlay and 16-byte prefix"
        author = "PacketPursuit"
        date = "2026-07-23"
        family = "unclassified-autoit-compiled"
    strings:
        $au3_header = "AU3!EA06"
        $prefix = { a3 48 4b be 98 6c 4a a9 99 4c 53 0a 86 d6 48 7d }
        $mz = "MZ"
    condition:
        $mz at 0 and
        $au3_header and
        $prefix in (0x60000..0xA0000) and
        pe.number_of_sections == 4 and
        pe.imports("WININET.dll")
}

Behavioral fingerprint

This binary is an AutoItSC single-file PE32 with a fabricated Jan 2012 PE timestamp, empty VS_VERSIONINFO, British English LangID, and a high-entropy encrypted script stored in the file overlay rather than .rsrc RT_RCDATA. It loads the full AutoIt v3 runtime (WSOCK32, WININET, ADVAPI32, GDI32, PSAPI, ICMP, USERENV, MPR, COMCTL32, WINMM, VERSION, COMDLG32). The overlay begins with a 16-byte prefix (a3484bbe986c4aa9994c530a86d6487d) before the AU3!EA06 script header. No plaintext C2 strings are present; network behavior is runtime-resolved by the compiled script.

IOC list

Indicator Value Type
SHA-256 8c88e73633c2d33ec35b35036e2a1c27b91c5b9aef3596b499f8bea3d2002806 Hash
Filename New_Order_List_Nov._2024.exe Filename
PE timestamp 0x4F25BAEC (2012-01-29 21:32:28 UTC) Timestamp
AutoIt version 3.3.8.1 Version
Overlay prefix a3484bbe986c4aa9994c530a86d6487d Bytes
LangID 080904B0 (British English) Metadata

Detection Signatures

  • MITRE ATT&CK: T1059.005 (AutoIt script execution) via the compiled interpreter.
  • Network: T1071.001 (Web Protocols) / T1095 (Non-Application Layer Protocol) inferred from WinInet/WinSock imports.
  • Persistence: T1547.001 (Registry Run) possible via ADVAPI32 RegSetValueExW imported by the runtime.
  • Discovery: T1083, T1057, T1012 inferred from standard AutoItSC API surface.
  • Collection: T1113, T1115, T1056.001 possible via GDI32 and USER32 imports.

References

  • [unclassified-autoit-compiled](/intel/families/unclassified-autoit-compiled.html) — cluster entity page
  • [autoit-compiled-script-dropper](/intel/concepts/autoit-compiled-script-dropper.html) — concept page
  • [autoit-overlay-script-placement](/intel/techniques/autoit-overlay-script-placement.html) — technique page

Provenance

  • file.txt — file utility output
  • pefile.txt — pefile Python library dump
  • exiftool.json — ExifTool metadata extraction
  • strings.txt — GNU strings output
  • rabin2-info.txt — radare2 binary header summary
  • binwalk.txt — binwalk embedded artefact scan
  • capa.txt — Mandiant capa capability detection (AutoIt file limitation)
  • yara.txt — YARA rule matches