Unclassified AutoIt Compiled PE32
Overview
Umbrella label for malware samples that are direct outputs of the AutoIt v3 single-file compiler (AutoItSC), producing a standalone PE32 executable with the interpreter runtime and compiled script bytecode fused into a single binary. These are distinct from autoit-compiled-script-dropper samples that drop a separate AutoIt3.exe + .a3x pair, and distinct from asgardprotector's IExpress SFX wrapping.
Currently fifty-eight confirmed samples:
|||||- 561c3ff6 (DHLXINVX0914534XPDF.exe, 352 KB encrypted SCRIPT resource in .rsrc) — Fifty-seventh confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with DHL airway-bill + invoice hybrid social-engineering lure (DHLXINVX0914534XPDF.exe). MSVC 14.16 (VS 2017) linker, genuine Dec 2024 PE timestamp. Script stored in .rsrc RT_RCDATA (not overlay). Empty VS_VERSIONINFO, British English LangID (080904B0). Eleven-icon suite in .rsrc (richest in cluster tied with dca60b6b). Standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, GDI, PSAPI, IPHLPAPI, USERENV, MPR). Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/561c3ff6b268566497a4e74bd61eed2058682100d2dfc9bb0e1edf78e743d3f0.html]
|||||- 798fa958 (DHLXINVX0914534XPDF.exe, UPX-packed transport of 561c3ff6, 743 KB packed → 1.21 MB unpacked) — Fifty-eighth confirmed sibling; UPX 4.2.2-compressed transport form of the already-analyzed 561c3ff6 payload; unpacks to identical SHA-256. Same DHL airway-bill + invoice hybrid lure, same AutoItSC v3.3.8.1 runtime, same 352 KB encrypted script in .rsrc, same empty VS_VERSIONINFO and British English LangID. Static-only.^[/intel/analyses/798fa95813d288933757022c943a26641e0fa710a5e94b294d161dc9787cbf16.html]
|||||- e08d5bcef (RFQ_3001-_Enquiry_for_FRP_and_GRP_Tanks_pdf.exe, 683 KB encrypted script in overlay) — Fifty-sixth confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with engineering-document social-engineering lure (FRP/GRP tank procurement RFQ). MSVC 10.0 (VS 2010) linker, fabricated Jan 2012 PE timestamp, 4 sections (no .reloc). Script stored in file overlay (eleventh sibling with this placement; breaks autoit-ripper). AU3!EA06 header at raw offset 0x99410. Empty VS_VERSIONINFO, British English LangID (080904B0). Four-icon suite in .rsrc. Standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, GDI, PSAPI, USERENV, MPR, COMCTL32, WINMM, VERSION, COMDLG32). Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/e08d5bcefbe1a2672589b457ddf11c7f2bfcb9d2151b75cea5213b820e56dc95.html]
||||- cbadab4d (RFQ.exe, May 2024, 328 KB encrypted SCRIPT resource in .rsrc) — Fifty-third confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with RFQ (Request for Quotation) procurement lure. MSVC 14.16 (VS 2017) linker, genuine May 2024 PE timestamp. Standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, GDI, PSAPI, IPHLPAPI, USERENV, MPR). Empty VS_VERSIONINFO. Four-icon suite. 8.00-entropy SCRIPT resource (327,551 bytes) in .rsrc RT_RCDATA. No plaintext C2, payload filenames, or shellcode strings recovered. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/cbadab4db7d56953ea63068a34e927a06601aa262975d88d7e045ed2d898d6c7.html]
||- 42c82e1d (New_Order.exe, 659 KB encrypted script in file overlay) — Forty-fifth confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with procurement-themed social-engineering lure. MSVC 10.0 (VS 2010) linker, 4 sections (no .reloc), fabricated Jan 2012 PE timestamp. Script stored in file overlay (ninth confirmed sibling with this placement), entropy 7.9997, AU3!EA06 header. Empty VS_VERSIONINFO. Standard AutoItSC import surface (WSOCK32, WININET, ADVAPI32, KERNEL32, GDI32, USER32, OLEAUT32, SHELL32, PSAPI, USERENV, MPR, COMCTL32, WINMM, VERSION, COMDLG32). No shellcode strings, payload filenames, or C2 indicators recovered statically. Static-only.^[/intel/analyses/42c82e1d79c735958322ed175e661aee9854ce6436c07e9c6621f2687469b04f.html]
|- 3f3540e1 (RFQ__ENQUIRY_ORDER__202400864.exe, Aug 2024, 390 KB encrypted SCRIPT resource in .rsrc) — Forty-fourth confirmed sibling; plain (non-UPX) AutoItSC single-file PE32 with procurement/RFQ social-engineering lure. Triple-underscore filename (RFQ__ENQUIRY_ORDER__202400864.exe) with numeric tracking code 202400864. VS_VERSIONINFO FileVersion 1.0.9.4, LangID 080904B0 (British English). MSVC 14.16 (VS 2017) linker, Aug 2024 genuine build timestamp. 11-icon suite in .rsrc. Standard AutoItSC import surface; no shellcode or payload filenames recovered in plaintext. Static-only.^[/intel/analyses/3f3540e185b31c70a7c89bfa8699a34e4c0e19a954a12597ea07791ccdb851d1.html]
||||- 4de51fe0 (GSTP_-_K3E0035.exe, Jul 2024, 294 KB encrypted SCRIPT resource in .rsrc) — Fortieth confirmed sibling
|||- 498f7bf3 (PAYMENT_INVOICE_RFQ_NEA062E23.exe, Jul 2024, UPX-packed transport, 277 KB encrypted SCRIPT resource in .rsrc) — Thirty-ninth confirmed sibling; AutoItSC v3.3.8.1+, MSVC 14.16 (VS 2017) linker. UPX 4.2.2 compression ratio 57.51%. Payment/invoice/RFQ social-engineering lure with fake tracking code NEA062E23. Script uses W30gfpz1 Caesar-3 hex-string decoder to unpack shellcode, allocates RWX via VirtualAlloc, executes at offset 0x23b0 via DllCallAddress. Shellcode builds 28-byte XOR key 5OOV6X5XTTFIAL29V28SLZ669JRP on the stack and decrypts asset (229 KB) into a stripped PE32 x86 inner payload (SHA-256 d72c10f8...). Inner payload has minimal imports (KERNEL32/ole32/OLEAUT32), no exports, 88 KB high-entropy .rsrc section. No C2 recovered. Static-only.^[/intel/analyses/498f7bf34e8e067e036bebc978ab35e74b9a3ef31cc6ff58d8542a2566518e7a.html]
||- 7c706df3 (REQUEST_FOR_QUOTATION.exe, Jul 2024, 291 KB encrypted SCRIPT resource in .rsrc) — Thirty-eighth confirmed sibling; AutoItSC v3.3.8.1, MSVC 12.0 (VS 2013) linker, plain PE32 (non-UPX). RFQ/procurement social-engineering lure. Script stored in .rsrc RT_RCDATA ID=SCRIPT with AU3!EA06 header; no overlay. Empty VS_VERSIONINFO. Full PCRE regex runtime, full WinInet/WinSock/ADVAPI32/GDI/PSAPI/ICMP import surface. No C2 recovered. Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/7c706df339eacd86f63c2ccf2aaa4709edaf5edbf24350afa421e3f34eb91a73.html]
|- 7bfa4723
7768873f(INVOICE.exe, 593 KB encrypted script in overlay) — Thirty-sixth confirmed sibling. AutoItSC v3.3.8.1, MSVC 10.0 (VS 2010) linker, plain PE32 (non-UPX), 4 sections (no.reloc). Invoice-themed social-engineering lure. Script stored in file overlay (seventh sibling with this placement; breaks autoit-ripper). Fabricated Jan 2012 PE timestamp. Empty VS_VERSIONINFO. Full WinInet/WinSock/ADVAPI32/GDI import surface. No C2 recovered. Static-only.^[/intel/analyses/7768873f4b7e6b6c594bdb182bcdde73d9f8ab3b13b19fe87b5fb32bc159dd01.html]
|- 763ae850 (RFQ_PROCUREMENT2024.exe, Jul 2024, 207 KB encrypted SCRIPT resource in .rsrc) — Thirty-fifth confirmed sibling; AutoItSC v3.3.8.1+, MSVC 12.0 (VS 2013) linker, plain PE32 (non-UPX). RFQ/procurement social-engineering lure. Drops ambiparous/Esher dual payload to %TEMP%. Esher is hex-encoded x86 shellcode decoded to 14 KB, executed at offset 0x23B0 via VirtualAlloc RWX + DllCallAddress. Custom S30K9CPG string-obfuscation function (Caesar-5 + XOR key "06"). Shellcode builds 22-byte XOR key K8A7IL856ASBIOOECH3P23 on the stack, decrypts ambiparous (189 KB) to a valid PE32 GUI payload, and process-hollows svchost.exe or .NET RegSvcs.exe to execute it reflectively. Inner payload is a stripped single-section PE32 with zero imports, zero exports, zero string surface, timestamp 2011-08-01. No C2 recovered. Static-only.^[/intel/analyses/763ae850f760ba69722a94ca74a6b88e2bb1a2185364ab358a360df2945bb5a8.html]
||||- 7317e559 (PURCHASE_ORDER_PO_#_2107-20454_24.exe, Jul 2024, 344 KB encrypted SCRIPT resource in .rsrc) — Thirty-fourth confirmed sibling
||- 68e48a8c (yoursalarypackage.com, Aug 2024, 529 KB encrypted SCRIPT resource in .rsrc) — Thirty-third confirmed sibling; UPX-packed transport layer over 891df280. Unpacks to identical SHA-256 891df280.... Same .com extension salary/payroll masquerade, same MSVC 14.16 linker, same empty VS_VERSIONINFO. Script placement in .rsrc (not overlay). UPX 4.2.2 compression ratio 64.94%. Static-only.^[/intel/analyses/68e48a8c19e8d95c80445e5d6290802a6c69ba25d0b020789ddec0983f23a832.html]
| |- 64b37e90 (Quote#011698.exe, Aug 2024, 384 KB SCRIPT resource in .rsrc) — Thirty-first confirmed sibling; AutoItSC v3.3.8.1, MSVC 14.16 (VS 2017) linker, plain PE32 (non-UPX). Procurement/quotation social-engineering lure (Quote#011698.exe). Drops Nasalis/emboweling dual payload to %TEMP%. Emboweling (86 KB) is hex-obfuscated x86 shellcode decoded via novel Z30PER function (hex-split with interleaved noise padding), executed at offset 0x23b0 via VirtualAlloc RWX + DllCallAddress. Shellcode XOR-decrypts Nasalis (287 KB) with a 30-byte key (K6N462UY5STOB8GAAC0UF0J0UA752I) and transfers execution to the decrypted PE32 GUI payload. Nasalis is heavily stripped with near-zero string surface; inner payload unattributed. Static-only.^[/intel/analyses/64b37e90dd772573c46014c2fa8a1a7a1b69df4a6a16f573d0312360e404c60d.html]
| |- 6718622d (Final_order.exe, Jul 2024, 1.09 MB SCRIPT resource in .rsrc) — Thirty-second confirmed sibling; AutoItSC v3.3.8.1, MSVC 14.16 (VS 2017) linker, plain PE32 (non-UPX). Purchase-order social-engineering lure. Drops emboweling/Lityerses dual payload to %TEMP%. Lityerses is a 28 KB Caesar-3 hex-encoded x86 shellcode stub; decoded to 14 KB shellcode, allocated RWX, executed at offset 0x23b0 via DllCallAddress. Shellcode builds a 19-byte XOR key (KUO55NAQ262XEL4XOC9) on the stack, decrypts emboweling (271 KB) to a valid .NET Framework PE32, and transfers execution. Inner payload is confirmed AgentTesla infostealer (keylogger, screenshot, clipboard, SMTP exfil). Static-only.^[/intel/analyses/6718622d94d373a123cac9f8cc6789bc1132eed19a5a9232dd0454ee869d910c.html]
| |- 9e95f20b (SPECIFICATIONS,_BOQ_DOC_pdf.exe, Jul 2024, script in .rsrc) — Twenty-ninth confirmed sibling
||- b017d189 (untitled, Jul 2024, 274 KB SCRIPT resource in .rsrc) — Twenty-fifth confirmed sibling; AutoItSC v3.3.8.1, MSVC 12.0 linker, empty VS_VERSIONINFO. Drops misrun/Esher dual payload to %TEMP%. Shellcode builds 30-byte XOR key L0LWKP01SHGB7V5E80RSQOBIW2FAUF on the stack, decrypts misrun, a 268 KB .NET PE32 infostealer with keylogger/screenshot/SMTP-FTP-HTTP exfil capabilities, assembly GUID 256d2426-b4cc-4996-9a99-c8e915357eef. Custom K30ZWMBJJ string-obfuscation function (permutation + XOR key "AA"). Static-only. Second confirmed AgentTesla inner payload in corpus.^[/intel/analyses/b017d1897d3c5b5c51f02fafcbe48700943ebe0921c1c881d4f7ea37fe1eefdc.html]
|- bf0134ff (Scanned_Copy_Detailing_Customer_Remittance_and_Overdue_Statement.exe, Jul 2024, ~249 KB SCRIPT resource in .rsrc) — Twenty-sixth confirmed sibling; AutoItSC v3.3.8.1+, MSVC 12.0 linker (VS 2013), plain PE32 (non-UPX). Banking/accounts-receivable social-engineering lure — first "customer remittance" theme in cluster. Encrypted script header a3484bbe... with AU3!EA06 marker. Full WinInet/WinSock/ADVAPI32/GDI import surface. No plaintext C2 recovered; threat logic opaque without decompilation. Static-only.^[/intel/analyses/bf0134ffa22871a80c7bce17b5c8e258c87d962d20e20b7972702b01aee30c5e.html]
|- c310cb2e (#INV-24090166.exe, UPX-packed duplicate of e5647a2d, 988 KB packed → 1.36 MB unpacked) — Twenty-seventh confirmed sibling. UPX 4.2.2-compressed transport form of the already-analyzed e5647a2d payload; unpacks to identical SHA-256. AutoItSC v3.3.8.1, Jan 2012 PE timestamp, 710 KB encrypted script in overlay, invoice-themed lure. Same filename as unpacked sibling. Static-only.^[/intel/analyses/c310cb2e0a7ae884f2045bd163ab81fbd020d516970510c76897a0836ba4b190.html]
|- 6395396e (COPIA_DE_PAGO.exe, script in .rsrc) — Thirtieth confirmed sibling; AutoItSC single-file PE32, MSVC 14.16 (VS 2017) linker, Jul 2024 build timestamp. Spanish-language banking lure ("Copy of Payment"). Drops Hymenophyllaceae/isochronally dual payload to %TEMP%. isochronally is Caesar-2 shifted then hex-decoded to 14 KB x86 shellcode, executed at offset 9136 via VirtualAlloc RWX + DllCallAddress. Custom M30K3JL string obfuscation (Caesar shift, keys 2 and 3). Hymenophyllaceae is a 240 KB encrypted inner payload with no recoverable PE header. No plaintext C2 recovered. Static-only.^[/intel/analyses/6395396ea7ab2d1c35062f10ef2cad39e5c42a5f8ff50d6a6564d76259542b03.html]
||- 941a189b (24099762P2024091901KYRQA.exe, 601 KB encrypted script in overlay) — Twenty-eighth confirmed sibling. AutoItSC v3.3.8.1, MSVC 10.0 (VS 2010) linker, fabricated Jan 2012 PE timestamp, plain PE32 (non-UPX). Logistics-tracking-code filename masquerade (24099762P2024091901KYRQA.exe) — numeric suffix + date stamp + alphanumeric code, suggesting supply-chain/freight-forwarding targeting. Fifth sibling with overlay script placement (after ff84806a, f346b7e9, e5647a2d, d990bd1b6, a8beee89). Full WinInet/WinSock/ADVAPI32/PSAPI/ICMP import surface. Empty VS_VERSIONINFO. Static-only.^[/intel/analyses/941a189bd84102c13255835bb2f4df77d9cb126be4e54faa179b9de469375fbe.html]
|- accd2ccd (PO-22012025-RFQ.exe, Oct 2024, 200 KB SCRIPT resource in .rsrc
|- aa4d237c (CF-INV._233348900RFP.exe, Aug 2024, 274 KB SCRIPT resource in .rsrc) — Twenty-third confirmed sibling; procurement/invoice lure, AutoItSC v3.3.8.1, MSVC 14.16 linker. Drops endochylous/contrapose dual-resource pair to %TEMP%, then decrypts and reflectively loads endochylous via a dedicated shellcode intermediary (contrapose). Caesar-5 string obfuscation (O30MJJHT), XOR key "WH". Static-only.^[/intel/analyses/aa4d237c7a9b4ec7915c582ad703c886422d59ceb40ded57307d7da15ec9bfc8.html]
|- 2d720f57 (Purchase_Order_423737.exe, Sep 2024, 258 KB SCRIPT resource in .rsrc) — Forty-sixth confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with procurement-themed social-engineering lure and numeric tracking-code suffix 423737. Distinctive VS_VERSIONINFO: CompanyName "Charley", FileVersion "3.5.5.7" — a cluster outlier, as most siblings present empty version blocks. MSVC 12.0 (VS 2013) linker, genuine Sep 2024 PE timestamp (not fabricated Jan 2012). British English LangID (080904B0). Four-icon suite. Standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, GDI, PSAPI, IPHLPAPI, USERENV, MPR). No plaintext C2 recovered. Static-only.^[/intel/analyses/2d720f57766050b9ac19ab38c1352f7b064bf194a616613468befdcaf4e51ff3.html]
|- ded287fe (ITHitech_Park_Project,_Bangladesh.exe, Sep 2024, 805 KB SCRIPT resource in .rsrc) — Twentieth confirmed sibling; plain (non-UPX) AutoItSC single-file PE32 with IT-park development-project lure, MSVC 14.16 linker, empty VS_VERSIONINFO, 15-icon suite, full PCRE regex runtime, standard WinInet/WinSock/ADVAPI32/GDI import surface. Largest SCRIPT resource in cluster to date (805 KB vs. 932 KB max from f0059bee). Static-only.^[/intel/analyses/ded287fe446fde8886980755b85e296b7cccd68b9abb03bd62c0795da471c4f2.html]
|- c80ef443 ((RFQ-11345).exe, Jul 2024, 220 KB SCRIPT resource in .rsrc) — Fifteenth confirmed sibling
c9c81f5b(QUOTATION_-_E401723.exe, Jul 2024, 227 KB SCRIPT resource in.rsrc) — Sixteenth confirmed sibling; procurement quotation lure (QUOTATION_-_E401723.exe); MSVC 14.16 linker, Jul 2024 build; plain PE32 (non-UPX); empty VS_VERSIONINFO; full PCRE regex library; standard AutoItSC import surface; 256×256 PNG icon in.rsrc. Static-only.^[/intel/analyses/c9c81f5be1bd1b496eb08f067889383ebe1c90b7cf11be791d197e69160a3216.html]cca7d56d(BANK_DETAILS_RO83728274746272627362.exe, Sep 2024, 183 KB SCRIPT resource in.rsrc) — Seventeenth confirmed sibling; banking-details filename lure with long numeric suffix; MSVC 12.0 (VS 2013) linker; plain PE32 (non-UPX); empty VS_VERSIONINFO; full PCRE regex library; standard AutoItSC import surface with ADVAPI32 token manipulation and WinInet/WinSock C2 client. Smaller script payload than cluster average. Static-only.^[/intel/analyses/cca7d56dffd819b96dcc149a4cd08308aa40035b73930e409d83e6434932b68e.html]ac2ca060(AUG_SOA.exe, May 2023, 802 KB SCRIPT resource in.rsrc)2c6133ca(Invoice.exe, Jul 2024, 311 KB SCRIPT resource in.rsrc) — ten-month sibling with invoice lure, same toolchain, smaller payload.^[/intel/analyses/2c6133cab1050c0c1be6649a55b14f5c48298fd7cef042d97326acd068a14f2f.html]
Packed variant:fb495efe— UPX-compressed form of2c6133ca(685 KB packed → 1.14 MB unpacked). Unpacks to identical SHA-2562c6133ca...; same filename, same SCRIPT resource, same build timestamp. MalwareBazaar labelupx-dec. Preserved in the corpus assample.bin.^[/intel/analyses/fb495efe6d76194abc19fea6499c3d8f70cee6912b024676da2058bda8cb8322.html]ff84806a(past_years_visit_..._scanned.exe, Jan 2012 PE timestamp, 694 KB script in overlay) — oldest observed sibling; bureau-lure filename;AU3!EA06header in file overlay rather than.rsrc; same AutoItSC v3.3.8.1 runtime.^[/intel/analyses/ff84806a2a126d998d52b895d71e137acd313ca92dc0c1445bd0ba6509df7a4f.html]6cc26f7c(HAWB No Original 2...pdf.bat.exe, Sep 2024, 241 KB SCRIPT resource in.rsrc) — UPX-packed, logistics-themed shipping-lure with double-extension masquerade. OpenCTI umbrella labeldepumped; actual build fingerprint matches this cluster. Static-only.^[/intel/analyses/6cc26f7c50c9d2a309cb6de2059976acf46d3c50930a9e72e9d260c432b28f54.html]1d0834e7(ΛΕΙΤΕΙ ΤΙΜΟΛΟΓΙΟ.bat.exe, Sep 2024, 221 KB SCRIPT resource in.rsrc) — Plain (non-UPX) AutoItSC, Greek invoice-lure with.bat.exedouble extension. OpenCTI umbrella labeldepumped; same cluster fingerprint. Static-only.^[/intel/analyses/1d0834e7d4fe46aa143359a35c69bebc449fc1b1799af77eb96a4cbe320b6884.html]ef71e0f6(Public_Holiday_Notice_2024.exe, Sep 2024, 186 KB SCRIPT resource in.rsrc) — Smallest script in cluster; VS 2013 linker (oldest post-2020); plain (non-UPX) PE32; "public holiday notice" payroll/HR lure. Static-only.^[/intel/analyses/ef71e0f650ea8e2673398aa4cab67be6628090b1b6375b7b8e027f26885d46e1.html]f0059bee(INQUIRY_2024-SP0006-B(01)_INQ24-012207.exe, Aug 2024, 932 KB SCRIPT resource in.rsrc) — Largest script in cluster; procurement-themed B2B lure; MSVC 14.16 runtime; unsigned. Static-only.^[/intel/analyses/f0059beebd2edd77495f1b94c756a6706052c3356aca19cf4807ee780629d15f.html]f2be9e06(PO_#86637.exe, Sep 2024, 417 KB SCRIPT resource in.rsrc) — Procurement/purchase-order lure; MSVC 14.16; plain PE32 (non-UPX); notable for embedded PCRE regex library strings (error messages + Unicode script-name table) suggesting script-side pattern harvesting. Static-only.^[/intel/analyses/f2be9e06fff932ac45101a0b28b07379fad8b868697b2bd95af141a01afa5f16.html]f346b7e9(PO-A1702108.exe, Jan 2012 PE timestamp, 659 KB script in overlay) — Ninth confirmed sibling; purchase-order procurement lure; same AutoItSC v3.3.8.1 runtime with script stored in file overlay (matchesff84806aplacement, not.rsrc). Full PCRE error-message table present. Static-only.^[/intel/analyses/f346b7e98f063bedfc73d0058393cee6cd7d2089831a9176841567b3cc4acb8a.html]f3a48a8c(PO20240627-001.exe, Jun 2024, 313 KB SCRIPT resource in.rsrc) — Tenth confirmed sibling; purchase-order lure matching PE build date exactly (2024-06-27); MSVC 14.0 (VS 2013 linker); plain PE32 (non-UPX); PCRE regex runtime present (same trait asf2be9e06); full ADVAPI32 token-manipulation surface. Static-only.^[/intel/analyses/f3a48a8c0394a72abf464dcf8b77420f0c5cba528c71bdc017dd692db031d69b.html]f51bc678(FDA.exe, Jul 2024, 196 KB SCRIPT resource in.rsrc) — Eleventh confirmed sibling; US government-agency masquerade (FDA regulatory lure) with 256×256 Adobe Acrobat PDF icon in.rsrc; smallest SCRIPT payload in cluster (~196 KB vs. 932 KB max); MSVC 14.16 runtime; empty VS_VERSIONINFO; PCRE regex library present. Static-only.^[/intel/analyses/f51bc678c27d1ed02c3bec276870a0daa0b61caec551c3cb8ce2c2078fa3aab9.html]f527ce01(1012024.exe, Jul 2024, 413 KB SCRIPT resource in.rsrc) — Twelfth confirmed sibling; generic numeric-date masquerade (suggesting 2024-10-01 deployment), 12-size icon suite in.rsrc, empty VS_VERSIONINFO, PCRE regex library present, mid-large script size comparable tof2be9e06. Static-only.^[/intel/analyses/f527ce01385b6be548d98cee6f022a96671c76c12b9430c13b5fa1a63e33e8d7.html]e5647a2d(#INV-24090166.exe, 710 KB script in overlay) — Thirteenth confirmed sibling; invoice-themed lure (#INV-24090166.exe); AutoItSC v3.3.8.1 with Jan 2012 PE timestamp; script stored in file overlay (third sibling with this placement); full WinInet/WinSock/ADVAPI32/GDI import surface including ICMP.DLL reconnaissance; PCRE regex runtime present; unsigned. Static-only.^[/intel/analyses/e5647a2dedd25289341cc36131ea33f2404e652c38eb81ac4d18f89898a65f04.html]f618a861(DHL_AWB_TRACKING_DETAILS.exe, Jul 2024, 237 KB SCRIPT resource in.rsrc) — Fourteenth confirmed sibling; DHL airway-bill tracking logistics lure; MSVC 12.0 (VS 2013) linker; plain PE32 (non-UPX); empty VS_VERSIONINFO; four-icon suite with DHL document masquerade; full PCRE regex library present; standard AutoItSC import surface. Static-only.^[/intel/analyses/f618a8619ab45629df06d80a6d5fec78962a679dbaaca29cf51cf9261973486f.html]
|- 54ad2eac (LOI_EN_590_10_PPM_and_Jet_A-1.exe, Aug 2024, 265 KB SCRIPT resource in .rsrc) — Forty-first confirmed sibling; plain (non-UPX) AutoItSC single-file PE32 with aviation fuel-specification lure (LOI_EN_590_10_PPM_and_Jet_A-1.exe — Limiting Oxygen Index / Jet A-1). Novel L300YQJRH stride-3 decimal-hex string obfuscation: every 3rd character is noise (decimal digit), first two chars per group are hex bytes. Drops maneuverability/sulfhydric dual payload to %TEMP%; shellcode executes at offset 9136 via DllCallAddress after VirtualAlloc RWX allocation. Timing gate via GetTickCount/Sleep delta check. Inner payload (maneuverability, 268 KB, entropy 7.91) encrypted; no C2 recovered statically. Static-only.^[/intel/analyses/54ad2eac7f23adb2cd0e9c6f287268a66679e3c3e18009d5b59dcb3485a19fc6.html]
|- d86e0912 (AUG_SOA.exe, Sep 2024, 802 KB SCRIPT resource in .rsrc) — Eighteenth confirmed sibling; UPX-packed AutoItSC single-file PE32 with business-document lure (AUG_SOA.exe — August Statement of Account); MSVC 14.14 (VS 2017) linker; empty VS_VERSIONINFO; full WinInet/WinSock/ADVAPI32/GDI import surface with token impersonation and process injection primitives. Largest script payload in cluster. Static-only.^[/intel/analyses/d86e0912502ef1c49a35151275b7473ccd62d6e49fa14ad02cdc817b60499a07.html]
-
d990bd1b6(Payment_Reference_SOA_Pending_Balance_Updated.exe, Jan 2012, 327 KB script in overlay) — Nineteenth confirmed sibling; banking/SOA-themed lure; AutoItSC v3.3.8.1 with Jan 2012 PE timestamp; script stored in file overlay (fourth sibling with this placement); standard WinInet/WinSock/ADVAPI32/GDI import surface; MSVC 10.0 (VS 2010) linker. Static-only.^[/intel/analyses/d990bd1b64d3875667e04aa35e36697d4c85e5a704676afb4cacee346638dd11.html] -
a8beee89eb72— Untitled PE32, 1.30 MB, Jan 2012 PE timestamp, ~274 KB encrypted script in overlay (fifth sibling with this placement); AutoItSC v3.3.8.1; decompiled script reveals dual-path payload delivery ($EFDJELXBSdisk drop to%TEMP%\resharpen+$TWUOSLLNJTmemory injection viaVirtualProtect→CallWindowProcat offset0x23A0); customTIYHOWEDONstring-obfuscation function usingwqdfrowvjunk-token stripping; no plaintext C2 recovered. Static-only. Low confidence.^[/intel/analyses/a8beee89eb72948b3fd255c6a1f5bab0300161aa0e32ba0aaffe5653b75111d0.html]
|||- 0854c21e (1012024.exe, Jul 2024, 412 KB encrypted script in .rsrc) — Forty-seventh confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with generic numeric-date masquerade (1012024.exe). MSVC 14.16 (VS 2017) linker, genuine Jul 2024 PE timestamp. Drops Hegeleos/turbinate dual payload to %TEMP%. turbinate is Caesar-3 hex-encoded x86 shellcode (28 KB), decoded by X30oR, allocated RWX, executed at offset 0x23B0 via DllCallAddress. Hegeleos (368 KB, entropy 7.95) is the encrypted inner payload decrypted at runtime by the shellcode. Build paths recovered: D:\xampp\htdocs\QMCY6SFIQG4ORLPXDS\ — XAMPP-hosted compilation environment. Static-only.^[/intel/analyses/0854c21ed7648b1d45e780c75bf6dc9e72858c93caf2828ff5af718c21f63f13.html]
||||- db9d07fd (Inv_022437.exe, Nov 2024, 690 KB encrypted SCRIPT resource in .rsrc) — Fifty-fourth confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with invoice-themed social-engineering lure (Inv_022437.exe). MSVC 14.16 (VS 2017) linker, genuine Nov 2024 PE timestamp. British English LangID (080904B0). Empty VS_VERSIONINFO. Nine-icon suite in .rsrc + 2 group icons. Standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, GDI, PSAPI, IPHLPAPI, USERENV, MPR). Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Script stored in .rsrc RT_RCDATA (not overlay). Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/db9d07fdf41273b436641d6505e1fb8d8d17bd3acd400194c1a51174bc9e66d7.html]
|- dca60b6b (COMMECIAL_INVOICE_AND_DHL_AWB_TRACKING_DETAILS.exe, Dec 2024, 493 KB encrypted SCRIPT resource in .rsrc) — Fifty-fifth confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with DHL airway-bill / invoice social-engineering lure. MSVC 12.0 (VS 2013) linker, genuine Dec 2024 PE timestamp. British English LangID (080904B0). Empty VS_VERSIONINFO. Eleven-icon suite (richest DHL-themed variant). Standard AutoItSC import surface. Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Script stored in .rsrc RT_RCDATA (not overlay). Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/dca60b6ba188e4f8886afd5002c8a4ab49e27f70e0c81dafa4cb3bbecfb3b38a.html]
|- c6c17d403f (Approved_686777-707987-098879896886.exe, Nov 2024, 344 KB encrypted SCRIPT resource in .rsrc) — Fifty-first confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with procurement-approval social-engineering lure and triple-numeric tracking-code filename (Approved_686777-707987-098879896886.exe). MSVC 11.0 (VS 2012) linker, genuine Nov 2024 PE timestamp (first post-Nov 2024 sibling in cluster). British English LangID (080904B0). Empty VS_VERSIONINFO. 11-icon suite in .rsrc. Standard AutoItSC import surface (WSOCK32, WININET, KERNEL32, USER32, GDI32, ADVAPI32, SHELL32, ole32, OLEAUT32, MPR, IPHLPAPI, PSAPI, USERENV, UxTheme, VERSION, WINMM, COMCTL32, COMDLG32). Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Script stored in .rsrc RT_RCDATA (not overlay). Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/c6c17d403f4d42946bee192df3559fb09087f030ffcc7c41d73b9fee76eb547b.html]
Build Stack Typically Observed
- Compiler: MSVC 14.x (VS 2017–2019) — the AutoItSC runtime is itself a C++ project
- Linker: Microsoft linker 14.x
- Script language: AutoIt v3 (BASIC-like scripting for Windows automation)
- Output format: PE32 x86 GUI or console, 5 sections (
.text,.rdata,.data,.rsrc,.reloc) - Script resource: Resource type
10(RT_RCDATA) IDSCRIPT, typically 200 KB–1 MB, encrypted/compiled bytecode withAU3!EA06header - Signing: Usually unsigned (no Authenticode)
- PDB: None
- Version info: Often minimal or empty VS_VERSIONINFO
Deploy / TTPs Typically Observed
Because the script logic is opaque, TTPs are inferred from the AutoIt runtime import table and known AutoIt malware patterns:
- Execution: T1059.005 (Command and Scripting Interpreter: Visual Basic / AutoIt) — the compiled script runs inside the AutoIt interpreter
- Network: T1071.001 (Web Protocols) via WinInet; T1095 (Non-Application Layer Protocol) via WinSock — HTTP/FTP/raw socket C2
- Persistence: T1547.001 (Registry Run) via
RegSetValueExW; T1053.005 (Scheduled Task) via AutoItRunor COM APIs - Discovery: T1083 (File and Directory Discovery), T1057 (Process Discovery), T1012 (Query Registry)
- Collection: T1113 (Screen Capture) via GDI32, T1115 (Clipboard Data), T1056.001 (Keylogging) via
GetAsyncKeyState - Evasion: Compiled script encryption provides natural static obfuscation; no anti-debug in the runtime itself
Variants / Aliases
- Single-file PE32 (this entity): Interpreter + script in one PE. No external files.
- Double-file
.a3x: SeparateAutoIt3.exe+.a3xscript. Documented under autoit-compiled-script-dropper and observed in asgardprotector. - IExpress SFX wrapped: Outer
wextract.execontaining AutoIt3 +.a3x. Observed in asgardprotector and 54e64e.
Notable Analyses
ac2ca060—AUG_SOA.exe, 1.7 MB, business-lure filename, 802 KB compiled SCRIPT resource in.rsrc, full WinInet/WinSock/GDI import table.^[/intel/analyses/ac2ca0601a108d722b78f1b6404117f72144d74d3b37a76ed9782d20cff2384b.html]2c6133ca—Invoice.exe, 1.14 MB, invoice-lure filename, 311 KB compiled SCRIPT resource in.rsrc, Jul 2024 build. Full WinInet/WinSock/GDI/ADVAPI32 token-manipulation import table.^[/intel/analyses/2c6133cab1050c0c1be6649a55b14f5c48298fd7cef042d97326acd068a14f2f.html]ff84806a—past_years_visit_..._scanned.exe, 1.34 MB, bureau-lure filename, 694 KB script in overlay (not.rsrc), Jan 2012 PE timestamp, AutoItSC v3.3.8.1. AddsICMP.DLLreconnaissance imports and oldest observed build in cluster.^[/intel/analyses/ff84806a2a126d998d52b895d71e137acd313ca92dc0c1445bd0ba6509df7a4f.html]e5647a2d—#INV-24090166.exe, 1.36 MB, Jan 2012 AutoItSC v3.3.8.1, 710 KB encrypted script in overlay, invoice lure. Full WinInet/WinSock/ADVAPI32/GDI/ICMP imports.^[/intel/analyses/e5647a2dedd25289341cc36131ea33f2404e652c38eb81ac4d18f89898a65f04.html]f618a861—DHL_AWB_TRACKING_DETAILS.exe, 1.08 MB, Jul 2024 build, 237 KB encrypted SCRIPT in.rsrc, DHL airway-bill logistics lure. MSVC 12.0 linker, empty VS_VERSIONINFO, four-icon suite, PCRE regex runtime. Standard AutoItSC import surface. Static-only.^[/intel/analyses/f618a8619ab45629df06d80a6d5fec78962a679dbaaca29cf51cf9261973486f.html]7768873f—INVOICE.exe, 1.30 MB, 593 KB encrypted script in overlay, invoice-themed lure. AutoItSC v3.3.8.1, MSVC 10.0 (VS 2010) linker, 4 sections (no.reloc). Seventh sibling with overlay script placement; breaks autoit-ripper. Fabricated Jan 2012 PE timestamp. Empty VS_VERSIONINFO, full PCRE regex library, standard WinInet/WinSock/ADVAPI32/GDI import surface. Static-only.^[/intel/analyses/7768873f4b7e6b6c594bdb182bcdde73d9f8ab3b13b19fe87b5fb32bc159dd01.html]fb5bc543—Custom_brief_declaration_notification_for_DHL_2024sept.exe, 1.29 MB, Jan 2012 PE timestamp, 690 KB encrypted script in overlay, AutoItSC v3.3.8.1, DHL logistics-themed lure. Empty VS_VERSIONINFO, 12-icon suite (richest in cluster), full PCRE regex library present, standard WinInet/WinSock/ADVAPI32/GDI import surface. Third sibling with overlay script placement (afterff84806a,e5647a2d). Static-only.^[/intel/analyses/fb5bc5438cc0be0978fc6723d1f063e32b1fd5df4d3c45599e474796d5d9ab6a.html]
Related Entities and Concepts
- autoit-compiled-script-dropper — concept page covering both single-file and two-file AutoIt deployment patterns
- asgardprotector — IExpress SFX family that frequently embeds AutoIt3 payloads
- 54e64e — umbrella label for Amadey-downloaded payloads including AutoIt variants
- iexpress-sfx-dropper — Microsoft Cabinet self-extractor repurposed as dropper
||- c7eabe28 (LPO_2024-00123765-00967645486.exe, 751 KB encrypted script in overlay) — Fifty-second confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with logistics/purchase-order social-engineering lure. MSVC 10.0 (VS 2010) linker, fabricated Jan 2012 PE timestamp, 4 sections (no .reloc). Script stored in file overlay (tenth sibling with this placement); AU3!EA06 header at raw offset 0x99200. Empty VS_VERSIONINFO, British English LangID (080904B0). Standard AutoItSC import surface (WSOCK32, WININET, KERNEL32, USER32, GDI32, ADVAPI32, SHELL32, ole32, OLEAUT32, PSAPI, USERENV, MPR, COMCTL32, WINMM, VERSION, COMDLG32). Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Static-only.^[/intel/analyses/c7eabe2849c6983691b237c2e95c429676d44b74f5ffcf1de1b7f1b306320136.html]
Capabilities
s30k9cpg-caesar-5-xor-obfuscation— Caesar-5 + XOR key"06"string decoder; first observed in sibling763ae850ambiparous-esher-dual-payload— biological/lexical nonce payload naming (ambiparous/Esher); observed in sibling763ae85022-byte-xor-key-stack-built— shellcode constructs 22-byte XOR key on stack via sequentialmov [ebp+disp], imm8; observed in sibling763ae850process-hollowing-svchost-regsvcs— process hollowing targetingsvchost.exewith .NETRegSvcs.exefallback; observed in sibling763ae850reflective-pe-loader-manual-mapping— manual PE mapping, IAT fix, relocation processing in shellcode; observed in sibling763ae850z30per-hex-string-obfuscation— novel hex-split interleaved-noise string decoder, first observed in this sampleagenttesla-payload-deliveryautoit-shellcode-xor-decryptork30zwmbjj-string-obfuscationm30k3jl-caesar-shift-obfuscationautoit-compiled-script-executionwininet-http-ftp-c2-clientwinsock-tcp-udp-networkingicmp-host-reconnaissanceregistry-read-write-persistencefile-system-enumeration-manipulationscreenshot-gdi-captureclipboard-hijackkeylogging-getasynckeystateprocess-enumeration-creation-injectioncompiled-bytecode-obfuscationtoken-privilege-escalationlateral-movement-credential-reusepcre-regex-data-harvestingvirtualprotect-callwindowproc-shellcode-injectionhex-encoded-payload-concatenationjunk-token-string-obfuscationdual-path-payload-deliveryu30jz3so7-permutation-xor-obfuscationturbinate-selectee-shellcode-stagingcaesar-3-string-obfuscation— Caesar-3 hex-string obfuscation used byP30r6oDfdecoder; observed in sibling6718622dp30r6odf-api-name-obfuscation— Caesar-3 string decoder for API names (oivrip762hpp→kernel32.dll); observed in sibling6718622demboweling-lityerses-dual-payload— biological/lexical nonce payload naming; observed in sibling6718622d19-byte-xor-key-stack-built— shellcode constructs XOR key on stack via sequentialmov [ebp+disp], imm8; observed in sibling6718622ddllcalladdress-shellcode-execution—DllCallAddressat fixed offset0x23b0afterVirtualAllocRWX; observed in sibling6718622dcaesar-3-hex-shellcode-staging— Caesar-3 hex-string obfuscation decoded byW30gfpz1and executed viaDllCallAddressat0x23b0; first observed in sample498f7bf3w30gfpz1-caesar-3-decoder— Specific decoder function nameW30gfpz1with shift value 3; observed in sample498f7bf328-byte-xor-key-stack-built— Shellcode constructs 28-byte XOR key on stack via sequentialmov [ebp+disp], imm8; observed in sample498f7bf3payment-invoice-rfq-tracking-code-masquerade— Triple-theme social-engineering filename (PAYMENT_INVOICE_RFQ_) with fake alphanumeric tracking code (NEA062E23); observed in sample498f7bf3maneuverability-sulfhydric-dual-payload— Biological/lexical nonce payload naming (maneuverability/sulfhydric); first observed in sample54ad2eacl300yqjrh-stride3-hex-decoder— Stride-3 decimal-hex string obfuscation: every 3rd character is noise (decimal digit), first two chars per group are hex bytes. Decoded viaStringMid(..., 2)+Chr(Dec(...)). First observed in sample54ad2eactiming-gate-gettickcount-sleep-delta— Anti-sandbox timing gate:GetTickCountbefore/afterSleep, check delta within(delta + 500) >= sleep_ms && (delta + 4294966796) <= sleep_ms. First observed in sample54ad2eacaviation-fuel-spec-masquerade— Industrial-engineering social-engineering lure using aviation fuel specification (LOI_EN_590_10_PPM_and_Jet_A-1.exe). First observed in sample54ad2eact30wl8asv-permutation-xor-obfuscation— Permutation-XOR string obfuscation with key"A", first observed in sample4de51fe0m31uy3g0-caesar-1-decoder— Caesar-1 hex decoder (chr(ord(c)-1), strip0xprefixes,bytes.fromhex), first observed in sample4de51fe0camellin-totten-dual-payload— Dual payload namedcamellin(encrypted inner payload) andtotten(shellcode hex source), first observed in sample4de51fe0gstp-tracking-code-masquerade— Fake-tracking-code filename masquerade (GSTP_-_K3E0035.exe), first observed in sample4de51fe0kernel32-stack-built-string— Shellcode buildskernel32.dllon stack viamov [ebp+disp], imm8pattern, first observed in sample4de51fe0rfq-enquiry-order-tracking-code-masquerade— Triple-underscore filename (RFQ__ENQUIRY_ORDER__202400864.exe) with numeric tracking code202400864, targeting Commonwealth English procurement departments. British English LangID (080904B0). First observed in sample3f3540e1.e30vaj-caesar-3-decoder— Caesar-3 string decoder (E30vaJ) with shift value 3, used for API names and payload filenames; first observed in sample0efed3b3acrorrheuma-nonsubmerged-dual-payload— Biological/lexical nonce payload naming (acrorrheuma/nonsubmerged); first observed in sample0efed3b317-byte-xor-key-stack-built— Shellcode constructs 17-byte XOR key on stack via sequentialmov [ebp+disp], imm8; first observed in sample0efed3b3agenttesla-smtp-c2-exfil— AgentTesla infostealer delivered with hardcoded SMTP C2 credentials (mail.rrcindia.co.in); first observed in sample0efed3b3p3059y1do-stride3-decimal-obfuscation— Stride-3 decimal string obfuscation viaP3059Y1DO(); every 3rd char is noise, first two chars parsed asDec()thenChr(). First observed in sample127c404aparachronistic-reaffection-dual-payload— Biological/lexical nonce payload naming (parachronistic/reaffection); first observed in sample127c404a15-byte-xor-key-stack-built— Shellcode constructs 15-byte XOR key on stack via sequentialmov [ebp+disp], imm8; first observed in sample127c404aprocess-hollowing-svchost-regsvcs— Process hollowing targetingsvchost.exewith .NETRegSvcs.exefallback; first observed in sample127c404adllcalladdress-shellcode-execution—DllCallAddressat fixed offset0x23b0afterVirtualAllocRWX; first observed in sample127c404a6ddv8-delimiter-hex-split-obfuscation— Hex-split string obfuscation with"6ddv8"delimiter stripped byBZAADLRV(); first observed in samplec3985bb5myriopodous-single-payload— Single encrypted companion payload (no dual biological/lexical naming); first observed in samplec3985bb530-byte-xor-key-stack-built— Longest observed XOR key (30 bytes) built on stack via sequentialmov [ebp+disp], imm8; first observed in samplec3985bb5payment-confirmation-invoice-masquerade—Payment_confirmation_for_IN311197&IN3114590.exelure with ampersand-separated invoice numbers; first observed in samplec3985bb5registry-run-cleanup—RegDeleteofHKCU\...\Run\HjR5Yalas anti-forensics/registry cleanup; first observed in samplec3985bb5triple-tracking-code-procurement-masquerade—Approved_686777-707987-098879896886.exelure with triple-dash-separated numeric tracking codes; first observed in samplec6c17d403f(Nov 2024). Build timestamp extends cluster activity to post-Nov 2024.msvc-11.0-autoitsc-linker— First sibling in cluster linked with Microsoft linker 11.0 (VS 2012); all previous siblings use MSVC 12.0+ or VS 2010. Observed in samplec6c17d403f.dhl-awb-tracking-masquerade— DHL airway-bill / logistics tracking social-engineering lure (DHL_AWB_TRACKING_DETAILS.exe,COMMECIAL_INVOICE_AND_DHL_AWB_TRACKING_DETAILS.exe); first observed in siblingf618a861, confirmed indca60b6b(Dec 2024).commercial-invoice-logistics-masquerade— Combined commercial invoice + logistics tracking lure with misspelled "COMMECIAL"; first observed in sampledca60b6b.frp-grp-tank-rfq-masquerade— Industrial engineering social-engineering lure using FRP/GRP (fiber-reinforced plastic / glass-reinforced plastic) tank procurement RFQ (RFQ_3001-_Enquiry_for_FRP_and_GRP_Tanks_pdf.exe). First observed in samplee08d5bcef.16-byte-overlay-prefix— 16-byte prefix (a3 48 4b be 98 6c 4a a9 99 4c 53 0a 86 d6 48 7d) before theAU3!EA06script header in the file overlay; possible additional encryption layer or file-inclusion artefact. First observed in samplee08d5bcef.
Forty-second: 5833e797
|- 5833e797 (Project_Commercial_Terms_And_Conditions_-_For_Manual_Sampling_System-Rev_SSGT_General_Ref_No-YASREF-318-CJ_G1-61_Phase_1D-BCD_17th-September-2024.exe, 1.93 MB, 1.11 MB encrypted script in .rsrc, YASREF refinery engineering-document lure. AutoItSC v3.3.8.1, MSVC 12.0 (VS 2013) linker, 5 sections, RT_RCDATA ID=SCRIPT at raw offset 0xD07B8, size 0x10FA30 (1,113,648 bytes). Four-icon suite, full PCRE regex runtime, empty VS_VERSIONINFO, standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, COMCTL32, MPR, GDI32). Largest SCRIPT resource in the cluster to date. Static-only.^[/intel/analyses/5833e7971bc43cfc52783e963373bcbec8a219ff406afb0a27f52861380b7b97.html]
||- 0854c21e (1012024.exe, Jul 2024, 412 KB encrypted script in .rsrc) — Forty-seventh confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with generic numeric-date masquerade (1012024.exe). MSVC 14.16 (VS 2017) linker, genuine Jul 2024 PE timestamp. Drops Hegeleos/turbinate dual payload to %TEMP%. turbinate is Caesar-3 hex-encoded x86 shellcode (28 KB), decoded by X30oR, allocated RWX, executed at offset 0x23B0 via DllCallAddress. Hegeleos (368 KB, entropy 7.95) is the encrypted inner payload decrypted at runtime by the shellcode. Build paths recovered: D:\xampp\htdocs\QMCY6SFIQG4ORLPXDS\ — XAMPP-hosted compilation environment. Static-only.^[/intel/analyses/0854c21ed7648b1d45e780c75bf6dc9e72858c93caf2828ff5af718c21f63f13.html]