AutoIt Hex-Split String Obfuscation
An AutoIt obfuscation pattern where hex-encoded payloads are broken into tiny fragments and distributed across hundreds of string concatenation lines (&=), each fragment polluted with a fixed delimiter that must be stripped at runtime.
Detection / Fingerprint
- AutoIt script with a global variable built via hundreds of
$VAR &= "..."lines. - The payload string starts with
0x(hex prefix). - A fixed short delimiter is inserted between every hex digit or small group of digits. The delimiter is stripped by a helper function using
StringInStr+StringTrimLeft. - Typical delimiters observed:
0qk5dd92(this sample),6504(FormBook cluster).
Implementation Pattern
Global $PBDWLMZ = "0qk5dd9200qk5dd92x0qk5dd9250qk5dd9250qk5dd928..."
$PBDWLMZ &= "9250qk5dd9280qk5dd9280qk5dd92b0qk5dd928..."
; ... 400+ lines
$PBDWLMZ = QATYOALFNE($PBDWLMZ) ; strips delimiter
; result: "0x558bec81ec..." → hex-decoded shellcode
The QATYOALFNE function wraps XLGMQNMAH($ECDESZUIVY, "0qk5dd92", ""), which walks the string, finds every occurrence of the delimiter, copies the bytes before it into an accumulator, skips past the delimiter, and repeats. ^[script.au3:5327-5350]
Defensive Countermeasures
- Script-aware deobfuscation: extract all
&=lines, concatenate quoted contents, strip the delimiter, thenbytes.fromhex(). - Behavioral: AutoIt processes creating RWX memory (
VirtualProtectwith0x40) are suspicious.
Pages Where Observed
- unattributed —
70848598primary sample - formbook — related
6504delimiter variant