typetechniqueconfidencehighcreated2026-07-05updated2026-07-05obfuscationautoitevasionscript

AutoIt Hex-Split String Obfuscation

An AutoIt obfuscation pattern where hex-encoded payloads are broken into tiny fragments and distributed across hundreds of string concatenation lines (&=), each fragment polluted with a fixed delimiter that must be stripped at runtime.

Detection / Fingerprint

  • AutoIt script with a global variable built via hundreds of $VAR &= "..." lines.
  • The payload string starts with 0x (hex prefix).
  • A fixed short delimiter is inserted between every hex digit or small group of digits. The delimiter is stripped by a helper function using StringInStr + StringTrimLeft.
  • Typical delimiters observed: 0qk5dd92 (this sample), 6504 (FormBook cluster).

Implementation Pattern

Global $PBDWLMZ = "0qk5dd9200qk5dd92x0qk5dd9250qk5dd9250qk5dd928..."
$PBDWLMZ &= "9250qk5dd9280qk5dd9280qk5dd92b0qk5dd928..."
; ... 400+ lines
$PBDWLMZ = QATYOALFNE($PBDWLMZ)   ; strips delimiter
; result: "0x558bec81ec..." → hex-decoded shellcode

The QATYOALFNE function wraps XLGMQNMAH($ECDESZUIVY, "0qk5dd92", ""), which walks the string, finds every occurrence of the delimiter, copies the bytes before it into an accumulator, skips past the delimiter, and repeats. ^[script.au3:5327-5350]

Defensive Countermeasures

  • Script-aware deobfuscation: extract all &= lines, concatenate quoted contents, strip the delimiter, then bytes.fromhex().
  • Behavioral: AutoIt processes creating RWX memory (VirtualProtect with 0x40) are suspicious.

Pages Where Observed