typeentityfamilyunclassified-autoit-compiledconfidencemediumcreated2026-06-16updated2026-07-22malware-familyloaderautoitevasionpec2persistencediscovery

Unclassified AutoIt Compiled PE32

Overview

Umbrella label for malware samples that are direct outputs of the AutoIt v3 single-file compiler (AutoItSC), producing a standalone PE32 executable with the interpreter runtime and compiled script bytecode fused into a single binary. These are distinct from autoit-compiled-script-dropper samples that drop a separate AutoIt3.exe + .a3x pair, and distinct from asgardprotector's IExpress SFX wrapping.

Currently fifty-eight confirmed samples:

|||||- 561c3ff6 (DHLXINVX0914534XPDF.exe, 352 KB encrypted SCRIPT resource in .rsrc) — Fifty-seventh confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with DHL airway-bill + invoice hybrid social-engineering lure (DHLXINVX0914534XPDF.exe). MSVC 14.16 (VS 2017) linker, genuine Dec 2024 PE timestamp. Script stored in .rsrc RT_RCDATA (not overlay). Empty VS_VERSIONINFO, British English LangID (080904B0). Eleven-icon suite in .rsrc (richest in cluster tied with dca60b6b). Standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, GDI, PSAPI, IPHLPAPI, USERENV, MPR). Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/561c3ff6b268566497a4e74bd61eed2058682100d2dfc9bb0e1edf78e743d3f0.html]

|||||- 798fa958 (DHLXINVX0914534XPDF.exe, UPX-packed transport of 561c3ff6, 743 KB packed → 1.21 MB unpacked) — Fifty-eighth confirmed sibling; UPX 4.2.2-compressed transport form of the already-analyzed 561c3ff6 payload; unpacks to identical SHA-256. Same DHL airway-bill + invoice hybrid lure, same AutoItSC v3.3.8.1 runtime, same 352 KB encrypted script in .rsrc, same empty VS_VERSIONINFO and British English LangID. Static-only.^[/intel/analyses/798fa95813d288933757022c943a26641e0fa710a5e94b294d161dc9787cbf16.html]

|||||- e08d5bcef (RFQ_3001-_Enquiry_for_FRP_and_GRP_Tanks_pdf.exe, 683 KB encrypted script in overlay) — Fifty-sixth confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with engineering-document social-engineering lure (FRP/GRP tank procurement RFQ). MSVC 10.0 (VS 2010) linker, fabricated Jan 2012 PE timestamp, 4 sections (no .reloc). Script stored in file overlay (eleventh sibling with this placement; breaks autoit-ripper). AU3!EA06 header at raw offset 0x99410. Empty VS_VERSIONINFO, British English LangID (080904B0). Four-icon suite in .rsrc. Standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, GDI, PSAPI, USERENV, MPR, COMCTL32, WINMM, VERSION, COMDLG32). Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/e08d5bcefbe1a2672589b457ddf11c7f2bfcb9d2151b75cea5213b820e56dc95.html]

||||- cbadab4d (RFQ.exe, May 2024, 328 KB encrypted SCRIPT resource in .rsrc) — Fifty-third confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with RFQ (Request for Quotation) procurement lure. MSVC 14.16 (VS 2017) linker, genuine May 2024 PE timestamp. Standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, GDI, PSAPI, IPHLPAPI, USERENV, MPR). Empty VS_VERSIONINFO. Four-icon suite. 8.00-entropy SCRIPT resource (327,551 bytes) in .rsrc RT_RCDATA. No plaintext C2, payload filenames, or shellcode strings recovered. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/cbadab4db7d56953ea63068a34e927a06601aa262975d88d7e045ed2d898d6c7.html]

||- 42c82e1d (New_Order.exe, 659 KB encrypted script in file overlay) — Forty-fifth confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with procurement-themed social-engineering lure. MSVC 10.0 (VS 2010) linker, 4 sections (no .reloc), fabricated Jan 2012 PE timestamp. Script stored in file overlay (ninth confirmed sibling with this placement), entropy 7.9997, AU3!EA06 header. Empty VS_VERSIONINFO. Standard AutoItSC import surface (WSOCK32, WININET, ADVAPI32, KERNEL32, GDI32, USER32, OLEAUT32, SHELL32, PSAPI, USERENV, MPR, COMCTL32, WINMM, VERSION, COMDLG32). No shellcode strings, payload filenames, or C2 indicators recovered statically. Static-only.^[/intel/analyses/42c82e1d79c735958322ed175e661aee9854ce6436c07e9c6621f2687469b04f.html]

|- 3f3540e1 (RFQ__ENQUIRY_ORDER__202400864.exe, Aug 2024, 390 KB encrypted SCRIPT resource in .rsrc) — Forty-fourth confirmed sibling; plain (non-UPX) AutoItSC single-file PE32 with procurement/RFQ social-engineering lure. Triple-underscore filename (RFQ__ENQUIRY_ORDER__202400864.exe) with numeric tracking code 202400864. VS_VERSIONINFO FileVersion 1.0.9.4, LangID 080904B0 (British English). MSVC 14.16 (VS 2017) linker, Aug 2024 genuine build timestamp. 11-icon suite in .rsrc. Standard AutoItSC import surface; no shellcode or payload filenames recovered in plaintext. Static-only.^[/intel/analyses/3f3540e185b31c70a7c89bfa8699a34e4c0e19a954a12597ea07791ccdb851d1.html]

||||- 4de51fe0 (GSTP_-_K3E0035.exe, Jul 2024, 294 KB encrypted SCRIPT resource in .rsrc) — Fortieth confirmed sibling

|||- 498f7bf3 (PAYMENT_INVOICE_RFQ_NEA062E23.exe, Jul 2024, UPX-packed transport, 277 KB encrypted SCRIPT resource in .rsrc) — Thirty-ninth confirmed sibling; AutoItSC v3.3.8.1+, MSVC 14.16 (VS 2017) linker. UPX 4.2.2 compression ratio 57.51%. Payment/invoice/RFQ social-engineering lure with fake tracking code NEA062E23. Script uses W30gfpz1 Caesar-3 hex-string decoder to unpack shellcode, allocates RWX via VirtualAlloc, executes at offset 0x23b0 via DllCallAddress. Shellcode builds 28-byte XOR key 5OOV6X5XTTFIAL29V28SLZ669JRP on the stack and decrypts asset (229 KB) into a stripped PE32 x86 inner payload (SHA-256 d72c10f8...). Inner payload has minimal imports (KERNEL32/ole32/OLEAUT32), no exports, 88 KB high-entropy .rsrc section. No C2 recovered. Static-only.^[/intel/analyses/498f7bf34e8e067e036bebc978ab35e74b9a3ef31cc6ff58d8542a2566518e7a.html]

||- 7c706df3 (REQUEST_FOR_QUOTATION.exe, Jul 2024, 291 KB encrypted SCRIPT resource in .rsrc) — Thirty-eighth confirmed sibling; AutoItSC v3.3.8.1, MSVC 12.0 (VS 2013) linker, plain PE32 (non-UPX). RFQ/procurement social-engineering lure. Script stored in .rsrc RT_RCDATA ID=SCRIPT with AU3!EA06 header; no overlay. Empty VS_VERSIONINFO. Full PCRE regex runtime, full WinInet/WinSock/ADVAPI32/GDI/PSAPI/ICMP import surface. No C2 recovered. Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/7c706df339eacd86f63c2ccf2aaa4709edaf5edbf24350afa421e3f34eb91a73.html]

|- 7bfa4723

  • 7768873f (INVOICE.exe, 593 KB encrypted script in overlay) — Thirty-sixth confirmed sibling. AutoItSC v3.3.8.1, MSVC 10.0 (VS 2010) linker, plain PE32 (non-UPX), 4 sections (no .reloc). Invoice-themed social-engineering lure. Script stored in file overlay (seventh sibling with this placement; breaks autoit-ripper). Fabricated Jan 2012 PE timestamp. Empty VS_VERSIONINFO. Full WinInet/WinSock/ADVAPI32/GDI import surface. No C2 recovered. Static-only.^[/intel/analyses/7768873f4b7e6b6c594bdb182bcdde73d9f8ab3b13b19fe87b5fb32bc159dd01.html]

|- 763ae850 (RFQ_PROCUREMENT2024.exe, Jul 2024, 207 KB encrypted SCRIPT resource in .rsrc) — Thirty-fifth confirmed sibling; AutoItSC v3.3.8.1+, MSVC 12.0 (VS 2013) linker, plain PE32 (non-UPX). RFQ/procurement social-engineering lure. Drops ambiparous/Esher dual payload to %TEMP%. Esher is hex-encoded x86 shellcode decoded to 14 KB, executed at offset 0x23B0 via VirtualAlloc RWX + DllCallAddress. Custom S30K9CPG string-obfuscation function (Caesar-5 + XOR key "06"). Shellcode builds 22-byte XOR key K8A7IL856ASBIOOECH3P23 on the stack, decrypts ambiparous (189 KB) to a valid PE32 GUI payload, and process-hollows svchost.exe or .NET RegSvcs.exe to execute it reflectively. Inner payload is a stripped single-section PE32 with zero imports, zero exports, zero string surface, timestamp 2011-08-01. No C2 recovered. Static-only.^[/intel/analyses/763ae850f760ba69722a94ca74a6b88e2bb1a2185364ab358a360df2945bb5a8.html]

||||- 7317e559 (PURCHASE_ORDER_PO_#_2107-20454_24.exe, Jul 2024, 344 KB encrypted SCRIPT resource in .rsrc) — Thirty-fourth confirmed sibling

||- 68e48a8c (yoursalarypackage.com, Aug 2024, 529 KB encrypted SCRIPT resource in .rsrc) — Thirty-third confirmed sibling; UPX-packed transport layer over 891df280. Unpacks to identical SHA-256 891df280.... Same .com extension salary/payroll masquerade, same MSVC 14.16 linker, same empty VS_VERSIONINFO. Script placement in .rsrc (not overlay). UPX 4.2.2 compression ratio 64.94%. Static-only.^[/intel/analyses/68e48a8c19e8d95c80445e5d6290802a6c69ba25d0b020789ddec0983f23a832.html]

| |- 64b37e90 (Quote#011698.exe, Aug 2024, 384 KB SCRIPT resource in .rsrc) — Thirty-first confirmed sibling; AutoItSC v3.3.8.1, MSVC 14.16 (VS 2017) linker, plain PE32 (non-UPX). Procurement/quotation social-engineering lure (Quote#011698.exe). Drops Nasalis/emboweling dual payload to %TEMP%. Emboweling (86 KB) is hex-obfuscated x86 shellcode decoded via novel Z30PER function (hex-split with interleaved noise padding), executed at offset 0x23b0 via VirtualAlloc RWX + DllCallAddress. Shellcode XOR-decrypts Nasalis (287 KB) with a 30-byte key (K6N462UY5STOB8GAAC0UF0J0UA752I) and transfers execution to the decrypted PE32 GUI payload. Nasalis is heavily stripped with near-zero string surface; inner payload unattributed. Static-only.^[/intel/analyses/64b37e90dd772573c46014c2fa8a1a7a1b69df4a6a16f573d0312360e404c60d.html]

| |- 6718622d (Final_order.exe, Jul 2024, 1.09 MB SCRIPT resource in .rsrc) — Thirty-second confirmed sibling; AutoItSC v3.3.8.1, MSVC 14.16 (VS 2017) linker, plain PE32 (non-UPX). Purchase-order social-engineering lure. Drops emboweling/Lityerses dual payload to %TEMP%. Lityerses is a 28 KB Caesar-3 hex-encoded x86 shellcode stub; decoded to 14 KB shellcode, allocated RWX, executed at offset 0x23b0 via DllCallAddress. Shellcode builds a 19-byte XOR key (KUO55NAQ262XEL4XOC9) on the stack, decrypts emboweling (271 KB) to a valid .NET Framework PE32, and transfers execution. Inner payload is confirmed AgentTesla infostealer (keylogger, screenshot, clipboard, SMTP exfil). Static-only.^[/intel/analyses/6718622d94d373a123cac9f8cc6789bc1132eed19a5a9232dd0454ee869d910c.html]

| |- 9e95f20b (SPECIFICATIONS,_BOQ_DOC_pdf.exe, Jul 2024, script in .rsrc) — Twenty-ninth confirmed sibling

||- b017d189 (untitled, Jul 2024, 274 KB SCRIPT resource in .rsrc) — Twenty-fifth confirmed sibling; AutoItSC v3.3.8.1, MSVC 12.0 linker, empty VS_VERSIONINFO. Drops misrun/Esher dual payload to %TEMP%. Shellcode builds 30-byte XOR key L0LWKP01SHGB7V5E80RSQOBIW2FAUF on the stack, decrypts misrun, a 268 KB .NET PE32 infostealer with keylogger/screenshot/SMTP-FTP-HTTP exfil capabilities, assembly GUID 256d2426-b4cc-4996-9a99-c8e915357eef. Custom K30ZWMBJJ string-obfuscation function (permutation + XOR key "AA"). Static-only. Second confirmed AgentTesla inner payload in corpus.^[/intel/analyses/b017d1897d3c5b5c51f02fafcbe48700943ebe0921c1c881d4f7ea37fe1eefdc.html]

|- bf0134ff (Scanned_Copy_Detailing_Customer_Remittance_and_Overdue_Statement.exe, Jul 2024, ~249 KB SCRIPT resource in .rsrc) — Twenty-sixth confirmed sibling; AutoItSC v3.3.8.1+, MSVC 12.0 linker (VS 2013), plain PE32 (non-UPX). Banking/accounts-receivable social-engineering lure — first "customer remittance" theme in cluster. Encrypted script header a3484bbe... with AU3!EA06 marker. Full WinInet/WinSock/ADVAPI32/GDI import surface. No plaintext C2 recovered; threat logic opaque without decompilation. Static-only.^[/intel/analyses/bf0134ffa22871a80c7bce17b5c8e258c87d962d20e20b7972702b01aee30c5e.html]

|- c310cb2e (#INV-24090166.exe, UPX-packed duplicate of e5647a2d, 988 KB packed → 1.36 MB unpacked) — Twenty-seventh confirmed sibling. UPX 4.2.2-compressed transport form of the already-analyzed e5647a2d payload; unpacks to identical SHA-256. AutoItSC v3.3.8.1, Jan 2012 PE timestamp, 710 KB encrypted script in overlay, invoice-themed lure. Same filename as unpacked sibling. Static-only.^[/intel/analyses/c310cb2e0a7ae884f2045bd163ab81fbd020d516970510c76897a0836ba4b190.html]

|- 6395396e (COPIA_DE_PAGO.exe, script in .rsrc) — Thirtieth confirmed sibling; AutoItSC single-file PE32, MSVC 14.16 (VS 2017) linker, Jul 2024 build timestamp. Spanish-language banking lure ("Copy of Payment"). Drops Hymenophyllaceae/isochronally dual payload to %TEMP%. isochronally is Caesar-2 shifted then hex-decoded to 14 KB x86 shellcode, executed at offset 9136 via VirtualAlloc RWX + DllCallAddress. Custom M30K3JL string obfuscation (Caesar shift, keys 2 and 3). Hymenophyllaceae is a 240 KB encrypted inner payload with no recoverable PE header. No plaintext C2 recovered. Static-only.^[/intel/analyses/6395396ea7ab2d1c35062f10ef2cad39e5c42a5f8ff50d6a6564d76259542b03.html]

||- 941a189b (24099762P2024091901KYRQA.exe, 601 KB encrypted script in overlay) — Twenty-eighth confirmed sibling. AutoItSC v3.3.8.1, MSVC 10.0 (VS 2010) linker, fabricated Jan 2012 PE timestamp, plain PE32 (non-UPX). Logistics-tracking-code filename masquerade (24099762P2024091901KYRQA.exe) — numeric suffix + date stamp + alphanumeric code, suggesting supply-chain/freight-forwarding targeting. Fifth sibling with overlay script placement (after ff84806a, f346b7e9, e5647a2d, d990bd1b6, a8beee89). Full WinInet/WinSock/ADVAPI32/PSAPI/ICMP import surface. Empty VS_VERSIONINFO. Static-only.^[/intel/analyses/941a189bd84102c13255835bb2f4df77d9cb126be4e54faa179b9de469375fbe.html]

|- accd2ccd (PO-22012025-RFQ.exe, Oct 2024, 200 KB SCRIPT resource in .rsrc

|- aa4d237c (CF-INV._233348900RFP.exe, Aug 2024, 274 KB SCRIPT resource in .rsrc) — Twenty-third confirmed sibling; procurement/invoice lure, AutoItSC v3.3.8.1, MSVC 14.16 linker. Drops endochylous/contrapose dual-resource pair to %TEMP%, then decrypts and reflectively loads endochylous via a dedicated shellcode intermediary (contrapose). Caesar-5 string obfuscation (O30MJJHT), XOR key "WH". Static-only.^[/intel/analyses/aa4d237c7a9b4ec7915c582ad703c886422d59ceb40ded57307d7da15ec9bfc8.html] |- 2d720f57 (Purchase_Order_423737.exe, Sep 2024, 258 KB SCRIPT resource in .rsrc) — Forty-sixth confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with procurement-themed social-engineering lure and numeric tracking-code suffix 423737. Distinctive VS_VERSIONINFO: CompanyName "Charley", FileVersion "3.5.5.7" — a cluster outlier, as most siblings present empty version blocks. MSVC 12.0 (VS 2013) linker, genuine Sep 2024 PE timestamp (not fabricated Jan 2012). British English LangID (080904B0). Four-icon suite. Standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, GDI, PSAPI, IPHLPAPI, USERENV, MPR). No plaintext C2 recovered. Static-only.^[/intel/analyses/2d720f57766050b9ac19ab38c1352f7b064bf194a616613468befdcaf4e51ff3.html]

|- ded287fe (ITHitech_Park_Project,_Bangladesh.exe, Sep 2024, 805 KB SCRIPT resource in .rsrc) — Twentieth confirmed sibling; plain (non-UPX) AutoItSC single-file PE32 with IT-park development-project lure, MSVC 14.16 linker, empty VS_VERSIONINFO, 15-icon suite, full PCRE regex runtime, standard WinInet/WinSock/ADVAPI32/GDI import surface. Largest SCRIPT resource in cluster to date (805 KB vs. 932 KB max from f0059bee). Static-only.^[/intel/analyses/ded287fe446fde8886980755b85e296b7cccd68b9abb03bd62c0795da471c4f2.html] |- c80ef443 ((RFQ-11345).exe, Jul 2024, 220 KB SCRIPT resource in .rsrc) — Fifteenth confirmed sibling

  • c9c81f5b (QUOTATION_-_E401723.exe, Jul 2024, 227 KB SCRIPT resource in .rsrc) — Sixteenth confirmed sibling; procurement quotation lure (QUOTATION_-_E401723.exe); MSVC 14.16 linker, Jul 2024 build; plain PE32 (non-UPX); empty VS_VERSIONINFO; full PCRE regex library; standard AutoItSC import surface; 256×256 PNG icon in .rsrc. Static-only.^[/intel/analyses/c9c81f5be1bd1b496eb08f067889383ebe1c90b7cf11be791d197e69160a3216.html]
  • cca7d56d (BANK_DETAILS_RO83728274746272627362.exe, Sep 2024, 183 KB SCRIPT resource in .rsrc) — Seventeenth confirmed sibling; banking-details filename lure with long numeric suffix; MSVC 12.0 (VS 2013) linker; plain PE32 (non-UPX); empty VS_VERSIONINFO; full PCRE regex library; standard AutoItSC import surface with ADVAPI32 token manipulation and WinInet/WinSock C2 client. Smaller script payload than cluster average. Static-only.^[/intel/analyses/cca7d56dffd819b96dcc149a4cd08308aa40035b73930e409d83e6434932b68e.html]
  • ac2ca060 (AUG_SOA.exe, May 2023, 802 KB SCRIPT resource in .rsrc)
  • 2c6133ca (Invoice.exe, Jul 2024, 311 KB SCRIPT resource in .rsrc) — ten-month sibling with invoice lure, same toolchain, smaller payload.^[/intel/analyses/2c6133cab1050c0c1be6649a55b14f5c48298fd7cef042d97326acd068a14f2f.html]
    Packed variant: fb495efe — UPX-compressed form of 2c6133ca (685 KB packed → 1.14 MB unpacked). Unpacks to identical SHA-256 2c6133ca...; same filename, same SCRIPT resource, same build timestamp. MalwareBazaar label upx-dec. Preserved in the corpus as sample.bin.^[/intel/analyses/fb495efe6d76194abc19fea6499c3d8f70cee6912b024676da2058bda8cb8322.html]
  • ff84806a (past_years_visit_..._scanned.exe, Jan 2012 PE timestamp, 694 KB script in overlay) — oldest observed sibling; bureau-lure filename; AU3!EA06 header in file overlay rather than .rsrc; same AutoItSC v3.3.8.1 runtime.^[/intel/analyses/ff84806a2a126d998d52b895d71e137acd313ca92dc0c1445bd0ba6509df7a4f.html]
  • 6cc26f7c (HAWB No Original 2...pdf.bat.exe, Sep 2024, 241 KB SCRIPT resource in .rsrc) — UPX-packed, logistics-themed shipping-lure with double-extension masquerade. OpenCTI umbrella label depumped; actual build fingerprint matches this cluster. Static-only.^[/intel/analyses/6cc26f7c50c9d2a309cb6de2059976acf46d3c50930a9e72e9d260c432b28f54.html]
  • 1d0834e7 (ΛΕΙΤΕΙ ΤΙΜΟΛΟΓΙΟ.bat.exe, Sep 2024, 221 KB SCRIPT resource in .rsrc) — Plain (non-UPX) AutoItSC, Greek invoice-lure with .bat.exe double extension. OpenCTI umbrella label depumped; same cluster fingerprint. Static-only.^[/intel/analyses/1d0834e7d4fe46aa143359a35c69bebc449fc1b1799af77eb96a4cbe320b6884.html]
  • ef71e0f6 (Public_Holiday_Notice_2024.exe, Sep 2024, 186 KB SCRIPT resource in .rsrc) — Smallest script in cluster; VS 2013 linker (oldest post-2020); plain (non-UPX) PE32; "public holiday notice" payroll/HR lure. Static-only.^[/intel/analyses/ef71e0f650ea8e2673398aa4cab67be6628090b1b6375b7b8e027f26885d46e1.html]
  • f0059bee (INQUIRY_2024-SP0006-B(01)_INQ24-012207.exe, Aug 2024, 932 KB SCRIPT resource in .rsrc) — Largest script in cluster; procurement-themed B2B lure; MSVC 14.16 runtime; unsigned. Static-only.^[/intel/analyses/f0059beebd2edd77495f1b94c756a6706052c3356aca19cf4807ee780629d15f.html]
  • f2be9e06 (PO_#86637.exe, Sep 2024, 417 KB SCRIPT resource in .rsrc) — Procurement/purchase-order lure; MSVC 14.16; plain PE32 (non-UPX); notable for embedded PCRE regex library strings (error messages + Unicode script-name table) suggesting script-side pattern harvesting. Static-only.^[/intel/analyses/f2be9e06fff932ac45101a0b28b07379fad8b868697b2bd95af141a01afa5f16.html]
  • f346b7e9 (PO-A1702108.exe, Jan 2012 PE timestamp, 659 KB script in overlay) — Ninth confirmed sibling; purchase-order procurement lure; same AutoItSC v3.3.8.1 runtime with script stored in file overlay (matches ff84806a placement, not .rsrc). Full PCRE error-message table present. Static-only.^[/intel/analyses/f346b7e98f063bedfc73d0058393cee6cd7d2089831a9176841567b3cc4acb8a.html]
  • f3a48a8c (PO20240627-001.exe, Jun 2024, 313 KB SCRIPT resource in .rsrc) — Tenth confirmed sibling; purchase-order lure matching PE build date exactly (2024-06-27); MSVC 14.0 (VS 2013 linker); plain PE32 (non-UPX); PCRE regex runtime present (same trait as f2be9e06); full ADVAPI32 token-manipulation surface. Static-only.^[/intel/analyses/f3a48a8c0394a72abf464dcf8b77420f0c5cba528c71bdc017dd692db031d69b.html]
  • f51bc678 (FDA.exe, Jul 2024, 196 KB SCRIPT resource in .rsrc) — Eleventh confirmed sibling; US government-agency masquerade (FDA regulatory lure) with 256×256 Adobe Acrobat PDF icon in .rsrc; smallest SCRIPT payload in cluster (~196 KB vs. 932 KB max); MSVC 14.16 runtime; empty VS_VERSIONINFO; PCRE regex library present. Static-only.^[/intel/analyses/f51bc678c27d1ed02c3bec276870a0daa0b61caec551c3cb8ce2c2078fa3aab9.html]
  • f527ce01 (1012024.exe, Jul 2024, 413 KB SCRIPT resource in .rsrc) — Twelfth confirmed sibling; generic numeric-date masquerade (suggesting 2024-10-01 deployment), 12-size icon suite in .rsrc, empty VS_VERSIONINFO, PCRE regex library present, mid-large script size comparable to f2be9e06. Static-only.^[/intel/analyses/f527ce01385b6be548d98cee6f022a96671c76c12b9430c13b5fa1a63e33e8d7.html]
  • e5647a2d (#INV-24090166.exe, 710 KB script in overlay) — Thirteenth confirmed sibling; invoice-themed lure (#INV-24090166.exe); AutoItSC v3.3.8.1 with Jan 2012 PE timestamp; script stored in file overlay (third sibling with this placement); full WinInet/WinSock/ADVAPI32/GDI import surface including ICMP.DLL reconnaissance; PCRE regex runtime present; unsigned. Static-only.^[/intel/analyses/e5647a2dedd25289341cc36131ea33f2404e652c38eb81ac4d18f89898a65f04.html]
  • f618a861 (DHL_AWB_TRACKING_DETAILS.exe, Jul 2024, 237 KB SCRIPT resource in .rsrc) — Fourteenth confirmed sibling; DHL airway-bill tracking logistics lure; MSVC 12.0 (VS 2013) linker; plain PE32 (non-UPX); empty VS_VERSIONINFO; four-icon suite with DHL document masquerade; full PCRE regex library present; standard AutoItSC import surface. Static-only.^[/intel/analyses/f618a8619ab45629df06d80a6d5fec78962a679dbaaca29cf51cf9261973486f.html]

|- 54ad2eac (LOI_EN_590_10_PPM_and_Jet_A-1.exe, Aug 2024, 265 KB SCRIPT resource in .rsrc) — Forty-first confirmed sibling; plain (non-UPX) AutoItSC single-file PE32 with aviation fuel-specification lure (LOI_EN_590_10_PPM_and_Jet_A-1.exe — Limiting Oxygen Index / Jet A-1). Novel L300YQJRH stride-3 decimal-hex string obfuscation: every 3rd character is noise (decimal digit), first two chars per group are hex bytes. Drops maneuverability/sulfhydric dual payload to %TEMP%; shellcode executes at offset 9136 via DllCallAddress after VirtualAlloc RWX allocation. Timing gate via GetTickCount/Sleep delta check. Inner payload (maneuverability, 268 KB, entropy 7.91) encrypted; no C2 recovered statically. Static-only.^[/intel/analyses/54ad2eac7f23adb2cd0e9c6f287268a66679e3c3e18009d5b59dcb3485a19fc6.html]

|- d86e0912 (AUG_SOA.exe, Sep 2024, 802 KB SCRIPT resource in .rsrc) — Eighteenth confirmed sibling; UPX-packed AutoItSC single-file PE32 with business-document lure (AUG_SOA.exe — August Statement of Account); MSVC 14.14 (VS 2017) linker; empty VS_VERSIONINFO; full WinInet/WinSock/ADVAPI32/GDI import surface with token impersonation and process injection primitives. Largest script payload in cluster. Static-only.^[/intel/analyses/d86e0912502ef1c49a35151275b7473ccd62d6e49fa14ad02cdc817b60499a07.html]

  • d990bd1b6 (Payment_Reference_SOA_Pending_Balance_Updated.exe, Jan 2012, 327 KB script in overlay) — Nineteenth confirmed sibling; banking/SOA-themed lure; AutoItSC v3.3.8.1 with Jan 2012 PE timestamp; script stored in file overlay (fourth sibling with this placement); standard WinInet/WinSock/ADVAPI32/GDI import surface; MSVC 10.0 (VS 2010) linker. Static-only.^[/intel/analyses/d990bd1b64d3875667e04aa35e36697d4c85e5a704676afb4cacee346638dd11.html]

  • a8beee89eb72 — Untitled PE32, 1.30 MB, Jan 2012 PE timestamp, ~274 KB encrypted script in overlay (fifth sibling with this placement); AutoItSC v3.3.8.1; decompiled script reveals dual-path payload delivery ($EFDJELXBS disk drop to %TEMP%\resharpen + $TWUOSLLNJT memory injection via VirtualProtectCallWindowProc at offset 0x23A0); custom TIYHOWEDON string-obfuscation function using wqdfrowv junk-token stripping; no plaintext C2 recovered. Static-only. Low confidence.^[/intel/analyses/a8beee89eb72948b3fd255c6a1f5bab0300161aa0e32ba0aaffe5653b75111d0.html]

|||- 0854c21e (1012024.exe, Jul 2024, 412 KB encrypted script in .rsrc) — Forty-seventh confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with generic numeric-date masquerade (1012024.exe). MSVC 14.16 (VS 2017) linker, genuine Jul 2024 PE timestamp. Drops Hegeleos/turbinate dual payload to %TEMP%. turbinate is Caesar-3 hex-encoded x86 shellcode (28 KB), decoded by X30oR, allocated RWX, executed at offset 0x23B0 via DllCallAddress. Hegeleos (368 KB, entropy 7.95) is the encrypted inner payload decrypted at runtime by the shellcode. Build paths recovered: D:\xampp\htdocs\QMCY6SFIQG4ORLPXDS\ — XAMPP-hosted compilation environment. Static-only.^[/intel/analyses/0854c21ed7648b1d45e780c75bf6dc9e72858c93caf2828ff5af718c21f63f13.html]

||||- db9d07fd (Inv_022437.exe, Nov 2024, 690 KB encrypted SCRIPT resource in .rsrc) — Fifty-fourth confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with invoice-themed social-engineering lure (Inv_022437.exe). MSVC 14.16 (VS 2017) linker, genuine Nov 2024 PE timestamp. British English LangID (080904B0). Empty VS_VERSIONINFO. Nine-icon suite in .rsrc + 2 group icons. Standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, GDI, PSAPI, IPHLPAPI, USERENV, MPR). Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Script stored in .rsrc RT_RCDATA (not overlay). Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/db9d07fdf41273b436641d6505e1fb8d8d17bd3acd400194c1a51174bc9e66d7.html]

|- dca60b6b (COMMECIAL_INVOICE_AND_DHL_AWB_TRACKING_DETAILS.exe, Dec 2024, 493 KB encrypted SCRIPT resource in .rsrc) — Fifty-fifth confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with DHL airway-bill / invoice social-engineering lure. MSVC 12.0 (VS 2013) linker, genuine Dec 2024 PE timestamp. British English LangID (080904B0). Empty VS_VERSIONINFO. Eleven-icon suite (richest DHL-themed variant). Standard AutoItSC import surface. Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Script stored in .rsrc RT_RCDATA (not overlay). Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/dca60b6ba188e4f8886afd5002c8a4ab49e27f70e0c81dafa4cb3bbecfb3b38a.html]

|- c6c17d403f (Approved_686777-707987-098879896886.exe, Nov 2024, 344 KB encrypted SCRIPT resource in .rsrc) — Fifty-first confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with procurement-approval social-engineering lure and triple-numeric tracking-code filename (Approved_686777-707987-098879896886.exe). MSVC 11.0 (VS 2012) linker, genuine Nov 2024 PE timestamp (first post-Nov 2024 sibling in cluster). British English LangID (080904B0). Empty VS_VERSIONINFO. 11-icon suite in .rsrc. Standard AutoItSC import surface (WSOCK32, WININET, KERNEL32, USER32, GDI32, ADVAPI32, SHELL32, ole32, OLEAUT32, MPR, IPHLPAPI, PSAPI, USERENV, UxTheme, VERSION, WINMM, COMCTL32, COMDLG32). Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Script stored in .rsrc RT_RCDATA (not overlay). Static-only (CAPE skipped — no Windows guest).^[/intel/analyses/c6c17d403f4d42946bee192df3559fb09087f030ffcc7c41d73b9fee76eb547b.html]

Build Stack Typically Observed

  • Compiler: MSVC 14.x (VS 2017–2019) — the AutoItSC runtime is itself a C++ project
  • Linker: Microsoft linker 14.x
  • Script language: AutoIt v3 (BASIC-like scripting for Windows automation)
  • Output format: PE32 x86 GUI or console, 5 sections (.text, .rdata, .data, .rsrc, .reloc)
  • Script resource: Resource type 10 (RT_RCDATA) ID SCRIPT, typically 200 KB–1 MB, encrypted/compiled bytecode with AU3!EA06 header
  • Signing: Usually unsigned (no Authenticode)
  • PDB: None
  • Version info: Often minimal or empty VS_VERSIONINFO

Deploy / TTPs Typically Observed

Because the script logic is opaque, TTPs are inferred from the AutoIt runtime import table and known AutoIt malware patterns:

  • Execution: T1059.005 (Command and Scripting Interpreter: Visual Basic / AutoIt) — the compiled script runs inside the AutoIt interpreter
  • Network: T1071.001 (Web Protocols) via WinInet; T1095 (Non-Application Layer Protocol) via WinSock — HTTP/FTP/raw socket C2
  • Persistence: T1547.001 (Registry Run) via RegSetValueExW; T1053.005 (Scheduled Task) via AutoIt Run or COM APIs
  • Discovery: T1083 (File and Directory Discovery), T1057 (Process Discovery), T1012 (Query Registry)
  • Collection: T1113 (Screen Capture) via GDI32, T1115 (Clipboard Data), T1056.001 (Keylogging) via GetAsyncKeyState
  • Evasion: Compiled script encryption provides natural static obfuscation; no anti-debug in the runtime itself

Variants / Aliases

Notable Analyses

  • ac2ca060AUG_SOA.exe, 1.7 MB, business-lure filename, 802 KB compiled SCRIPT resource in .rsrc, full WinInet/WinSock/GDI import table.^[/intel/analyses/ac2ca0601a108d722b78f1b6404117f72144d74d3b37a76ed9782d20cff2384b.html]
  • 2c6133caInvoice.exe, 1.14 MB, invoice-lure filename, 311 KB compiled SCRIPT resource in .rsrc, Jul 2024 build. Full WinInet/WinSock/GDI/ADVAPI32 token-manipulation import table.^[/intel/analyses/2c6133cab1050c0c1be6649a55b14f5c48298fd7cef042d97326acd068a14f2f.html]
  • ff84806apast_years_visit_..._scanned.exe, 1.34 MB, bureau-lure filename, 694 KB script in overlay (not .rsrc), Jan 2012 PE timestamp, AutoItSC v3.3.8.1. Adds ICMP.DLL reconnaissance imports and oldest observed build in cluster.^[/intel/analyses/ff84806a2a126d998d52b895d71e137acd313ca92dc0c1445bd0ba6509df7a4f.html]
  • e5647a2d#INV-24090166.exe, 1.36 MB, Jan 2012 AutoItSC v3.3.8.1, 710 KB encrypted script in overlay, invoice lure. Full WinInet/WinSock/ADVAPI32/GDI/ICMP imports.^[/intel/analyses/e5647a2dedd25289341cc36131ea33f2404e652c38eb81ac4d18f89898a65f04.html]
  • f618a861DHL_AWB_TRACKING_DETAILS.exe, 1.08 MB, Jul 2024 build, 237 KB encrypted SCRIPT in .rsrc, DHL airway-bill logistics lure. MSVC 12.0 linker, empty VS_VERSIONINFO, four-icon suite, PCRE regex runtime. Standard AutoItSC import surface. Static-only.^[/intel/analyses/f618a8619ab45629df06d80a6d5fec78962a679dbaaca29cf51cf9261973486f.html]
  • 7768873fINVOICE.exe, 1.30 MB, 593 KB encrypted script in overlay, invoice-themed lure. AutoItSC v3.3.8.1, MSVC 10.0 (VS 2010) linker, 4 sections (no .reloc). Seventh sibling with overlay script placement; breaks autoit-ripper. Fabricated Jan 2012 PE timestamp. Empty VS_VERSIONINFO, full PCRE regex library, standard WinInet/WinSock/ADVAPI32/GDI import surface. Static-only.^[/intel/analyses/7768873f4b7e6b6c594bdb182bcdde73d9f8ab3b13b19fe87b5fb32bc159dd01.html]
  • fb5bc543Custom_brief_declaration_notification_for_DHL_2024sept.exe, 1.29 MB, Jan 2012 PE timestamp, 690 KB encrypted script in overlay, AutoItSC v3.3.8.1, DHL logistics-themed lure. Empty VS_VERSIONINFO, 12-icon suite (richest in cluster), full PCRE regex library present, standard WinInet/WinSock/ADVAPI32/GDI import surface. Third sibling with overlay script placement (after ff84806a, e5647a2d). Static-only.^[/intel/analyses/fb5bc5438cc0be0978fc6723d1f063e32b1fd5df4d3c45599e474796d5d9ab6a.html]

Related Entities and Concepts

  • autoit-compiled-script-dropper — concept page covering both single-file and two-file AutoIt deployment patterns
  • asgardprotector — IExpress SFX family that frequently embeds AutoIt3 payloads
  • 54e64e — umbrella label for Amadey-downloaded payloads including AutoIt variants
  • iexpress-sfx-dropper — Microsoft Cabinet self-extractor repurposed as dropper

||- c7eabe28 (LPO_2024-00123765-00967645486.exe, 751 KB encrypted script in overlay) — Fifty-second confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with logistics/purchase-order social-engineering lure. MSVC 10.0 (VS 2010) linker, fabricated Jan 2012 PE timestamp, 4 sections (no .reloc). Script stored in file overlay (tenth sibling with this placement); AU3!EA06 header at raw offset 0x99200. Empty VS_VERSIONINFO, British English LangID (080904B0). Standard AutoItSC import surface (WSOCK32, WININET, KERNEL32, USER32, GDI32, ADVAPI32, SHELL32, ole32, OLEAUT32, PSAPI, USERENV, MPR, COMCTL32, WINMM, VERSION, COMDLG32). Full PCRE regex runtime. No plaintext C2, payload filenames, or shellcode strings recovered. Static-only.^[/intel/analyses/c7eabe2849c6983691b237c2e95c429676d44b74f5ffcf1de1b7f1b306320136.html]

Capabilities

  • s30k9cpg-caesar-5-xor-obfuscation — Caesar-5 + XOR key "06" string decoder; first observed in sibling 763ae850
  • ambiparous-esher-dual-payload — biological/lexical nonce payload naming (ambiparous / Esher); observed in sibling 763ae850
  • 22-byte-xor-key-stack-built — shellcode constructs 22-byte XOR key on stack via sequential mov [ebp+disp], imm8; observed in sibling 763ae850
  • process-hollowing-svchost-regsvcs — process hollowing targeting svchost.exe with .NET RegSvcs.exe fallback; observed in sibling 763ae850
  • reflective-pe-loader-manual-mapping — manual PE mapping, IAT fix, relocation processing in shellcode; observed in sibling 763ae850
  • z30per-hex-string-obfuscation — novel hex-split interleaved-noise string decoder, first observed in this sample
  • agenttesla-payload-delivery
  • autoit-shellcode-xor-decryptor
  • k30zwmbjj-string-obfuscation
  • m30k3jl-caesar-shift-obfuscation
  • autoit-compiled-script-execution
  • wininet-http-ftp-c2-client
  • winsock-tcp-udp-networking
  • icmp-host-reconnaissance
  • registry-read-write-persistence
  • file-system-enumeration-manipulation
  • screenshot-gdi-capture
  • clipboard-hijack
  • keylogging-getasynckeystate
  • process-enumeration-creation-injection
  • compiled-bytecode-obfuscation
  • token-privilege-escalation
  • lateral-movement-credential-reuse
  • pcre-regex-data-harvesting
  • virtualprotect-callwindowproc-shellcode-injection
  • hex-encoded-payload-concatenation
  • junk-token-string-obfuscation
  • dual-path-payload-delivery
  • u30jz3so7-permutation-xor-obfuscation
  • turbinate-selectee-shellcode-staging
  • caesar-3-string-obfuscation — Caesar-3 hex-string obfuscation used by P30r6oDf decoder; observed in sibling 6718622d
  • p30r6odf-api-name-obfuscation — Caesar-3 string decoder for API names (oivrip762hppkernel32.dll); observed in sibling 6718622d
  • emboweling-lityerses-dual-payload — biological/lexical nonce payload naming; observed in sibling 6718622d
  • 19-byte-xor-key-stack-built — shellcode constructs XOR key on stack via sequential mov [ebp+disp], imm8; observed in sibling 6718622d
  • dllcalladdress-shellcode-executionDllCallAddress at fixed offset 0x23b0 after VirtualAlloc RWX; observed in sibling 6718622d
  • caesar-3-hex-shellcode-staging — Caesar-3 hex-string obfuscation decoded by W30gfpz1 and executed via DllCallAddress at 0x23b0; first observed in sample 498f7bf3
  • w30gfpz1-caesar-3-decoder — Specific decoder function name W30gfpz1 with shift value 3; observed in sample 498f7bf3
  • 28-byte-xor-key-stack-built — Shellcode constructs 28-byte XOR key on stack via sequential mov [ebp+disp], imm8; observed in sample 498f7bf3
  • payment-invoice-rfq-tracking-code-masquerade — Triple-theme social-engineering filename (PAYMENT_INVOICE_RFQ_) with fake alphanumeric tracking code (NEA062E23); observed in sample 498f7bf3
  • maneuverability-sulfhydric-dual-payload — Biological/lexical nonce payload naming (maneuverability / sulfhydric); first observed in sample 54ad2eac
  • l300yqjrh-stride3-hex-decoder — Stride-3 decimal-hex string obfuscation: every 3rd character is noise (decimal digit), first two chars per group are hex bytes. Decoded via StringMid(..., 2) + Chr(Dec(...)). First observed in sample 54ad2eac
  • timing-gate-gettickcount-sleep-delta — Anti-sandbox timing gate: GetTickCount before/after Sleep, check delta within (delta + 500) >= sleep_ms && (delta + 4294966796) <= sleep_ms. First observed in sample 54ad2eac
  • aviation-fuel-spec-masquerade — Industrial-engineering social-engineering lure using aviation fuel specification (LOI_EN_590_10_PPM_and_Jet_A-1.exe). First observed in sample 54ad2eac
  • t30wl8asv-permutation-xor-obfuscation — Permutation-XOR string obfuscation with key "A", first observed in sample 4de51fe0
  • m31uy3g0-caesar-1-decoder — Caesar-1 hex decoder (chr(ord(c)-1), strip 0x prefixes, bytes.fromhex), first observed in sample 4de51fe0
  • camellin-totten-dual-payload — Dual payload named camellin (encrypted inner payload) and totten (shellcode hex source), first observed in sample 4de51fe0
  • gstp-tracking-code-masquerade — Fake-tracking-code filename masquerade (GSTP_-_K3E0035.exe), first observed in sample 4de51fe0
  • kernel32-stack-built-string — Shellcode builds kernel32.dll on stack via mov [ebp+disp], imm8 pattern, first observed in sample 4de51fe0
  • rfq-enquiry-order-tracking-code-masquerade — Triple-underscore filename (RFQ__ENQUIRY_ORDER__202400864.exe) with numeric tracking code 202400864, targeting Commonwealth English procurement departments. British English LangID (080904B0). First observed in sample 3f3540e1.
  • e30vaj-caesar-3-decoder — Caesar-3 string decoder (E30vaJ) with shift value 3, used for API names and payload filenames; first observed in sample 0efed3b3
  • acrorrheuma-nonsubmerged-dual-payload — Biological/lexical nonce payload naming (acrorrheuma / nonsubmerged); first observed in sample 0efed3b3
  • 17-byte-xor-key-stack-built — Shellcode constructs 17-byte XOR key on stack via sequential mov [ebp+disp], imm8; first observed in sample 0efed3b3
  • agenttesla-smtp-c2-exfil — AgentTesla infostealer delivered with hardcoded SMTP C2 credentials (mail.rrcindia.co.in); first observed in sample 0efed3b3
  • p3059y1do-stride3-decimal-obfuscation — Stride-3 decimal string obfuscation via P3059Y1DO(); every 3rd char is noise, first two chars parsed as Dec() then Chr(). First observed in sample 127c404a
  • parachronistic-reaffection-dual-payload — Biological/lexical nonce payload naming (parachronistic / reaffection); first observed in sample 127c404a
  • 15-byte-xor-key-stack-built — Shellcode constructs 15-byte XOR key on stack via sequential mov [ebp+disp], imm8; first observed in sample 127c404a
  • process-hollowing-svchost-regsvcs — Process hollowing targeting svchost.exe with .NET RegSvcs.exe fallback; first observed in sample 127c404a
  • dllcalladdress-shellcode-executionDllCallAddress at fixed offset 0x23b0 after VirtualAlloc RWX; first observed in sample 127c404a
  • 6ddv8-delimiter-hex-split-obfuscation — Hex-split string obfuscation with "6ddv8" delimiter stripped by BZAADLRV(); first observed in sample c3985bb5
  • myriopodous-single-payload — Single encrypted companion payload (no dual biological/lexical naming); first observed in sample c3985bb5
  • 30-byte-xor-key-stack-built — Longest observed XOR key (30 bytes) built on stack via sequential mov [ebp+disp], imm8; first observed in sample c3985bb5
  • payment-confirmation-invoice-masqueradePayment_confirmation_for_IN311197&IN3114590.exe lure with ampersand-separated invoice numbers; first observed in sample c3985bb5
  • registry-run-cleanupRegDelete of HKCU\...\Run\HjR5Yal as anti-forensics/registry cleanup; first observed in sample c3985bb5
  • triple-tracking-code-procurement-masqueradeApproved_686777-707987-098879896886.exe lure with triple-dash-separated numeric tracking codes; first observed in sample c6c17d403f (Nov 2024). Build timestamp extends cluster activity to post-Nov 2024.
  • msvc-11.0-autoitsc-linker — First sibling in cluster linked with Microsoft linker 11.0 (VS 2012); all previous siblings use MSVC 12.0+ or VS 2010. Observed in sample c6c17d403f.
  • dhl-awb-tracking-masquerade — DHL airway-bill / logistics tracking social-engineering lure (DHL_AWB_TRACKING_DETAILS.exe, COMMECIAL_INVOICE_AND_DHL_AWB_TRACKING_DETAILS.exe); first observed in sibling f618a861, confirmed in dca60b6b (Dec 2024).
  • commercial-invoice-logistics-masquerade — Combined commercial invoice + logistics tracking lure with misspelled "COMMECIAL"; first observed in sample dca60b6b.
  • frp-grp-tank-rfq-masquerade — Industrial engineering social-engineering lure using FRP/GRP (fiber-reinforced plastic / glass-reinforced plastic) tank procurement RFQ (RFQ_3001-_Enquiry_for_FRP_and_GRP_Tanks_pdf.exe). First observed in sample e08d5bcef.
  • 16-byte-overlay-prefix — 16-byte prefix (a3 48 4b be 98 6c 4a a9 99 4c 53 0a 86 d6 48 7d) before the AU3!EA06 script header in the file overlay; possible additional encryption layer or file-inclusion artefact. First observed in sample e08d5bcef.

Forty-second: 5833e797

|- 5833e797 (Project_Commercial_Terms_And_Conditions_-_For_Manual_Sampling_System-Rev_SSGT_General_Ref_No-YASREF-318-CJ_G1-61_Phase_1D-BCD_17th-September-2024.exe, 1.93 MB, 1.11 MB encrypted script in .rsrc, YASREF refinery engineering-document lure. AutoItSC v3.3.8.1, MSVC 12.0 (VS 2013) linker, 5 sections, RT_RCDATA ID=SCRIPT at raw offset 0xD07B8, size 0x10FA30 (1,113,648 bytes). Four-icon suite, full PCRE regex runtime, empty VS_VERSIONINFO, standard AutoItSC import surface (WinInet, WinSock, ADVAPI32, COMCTL32, MPR, GDI32). Largest SCRIPT resource in the cluster to date. Static-only.^[/intel/analyses/5833e7971bc43cfc52783e963373bcbec8a219ff406afb0a27f52861380b7b97.html]

||- 0854c21e (1012024.exe, Jul 2024, 412 KB encrypted script in .rsrc) — Forty-seventh confirmed sibling; AutoItSC v3.3.8.1 single-file PE32 with generic numeric-date masquerade (1012024.exe). MSVC 14.16 (VS 2017) linker, genuine Jul 2024 PE timestamp. Drops Hegeleos/turbinate dual payload to %TEMP%. turbinate is Caesar-3 hex-encoded x86 shellcode (28 KB), decoded by X30oR, allocated RWX, executed at offset 0x23B0 via DllCallAddress. Hegeleos (368 KB, entropy 7.95) is the encrypted inner payload decrypted at runtime by the shellcode. Build paths recovered: D:\xampp\htdocs\QMCY6SFIQG4ORLPXDS\ — XAMPP-hosted compilation environment. Static-only.^[/intel/analyses/0854c21ed7648b1d45e780c75bf6dc9e72858c93caf2828ff5af718c21f63f13.html]