typetechniquefamilyunclassified-autoit-compiledconfidencehighcreated2026-07-10updated2026-07-10autoitobfuscationstring-decodeanti-static-analysis

AutoIt Stride-3 Hex String Decoder (L300YQJRH)

A custom string-obfuscation function observed in compiled AutoIt3 single-file PE droppers. Decoded strings include API names (kernel32.dll, GetTickCount), type names (dword, long, ptr, str), and numeric constants (0x3000, 0x40), all of which are consumed by subsequent DllCall/DllCallAddress shellcode-staging logic.

Algorithm

Func L300YQJRH($W30HEPV)
    Local $Y311J = ""
    For $H32YUIB = 1 To StringLen($W30HEPV) Step 3
        Local $R34K1T = StringMid($W30HEPV, $H32YUib, 2)
        $Y311J &= Chr(Dec($R34k1t))
    Next
    Return $Y311J
EndFunc
  1. Iterate over the ciphertext in steps of 3.
  2. Extract the first 2 characters of each 3-character group.
  3. Interpret those 2 characters as a hexadecimal byte (Dec(...) in AutoIt = base-10 Val(...) but with hex prefix support).
  4. Convert to ASCII (Chr).

The 3rd character in every group is noise — a decimal digit 0-9 that has no semantic value and serves only to break naive hex-pair splitting.

Example

Ciphertext group Kept chars Hex byte ASCII
6BF 6B 0x6B k
65W 65 0x65 e
72B 72 0x72 r
6EY 6E 0x6E n
65R 65 0x65 e
6CF 6C 0x6C l

Full decode of 6BF65W72B6EY65R6CF33I32Y2EC64G6CF6CZkernel32.dll.

Distinction from sibling decoders

Decoder Family sample Mechanism Key/stride
T30WL8ASV 4de51fe0 Permutation + XOR key "A" Permutation table + XOR
M31UY3G0 4de51fe0 Caesar-1 shift on hex pairs Shift = 1
W30gfpz1 498f7bf3 Caesar-3 shift on hex pairs Shift = 3
S30K9CPG 763ae850 Caesar-5 shift then XOR "06" Shift = 5, XOR key = "06"
L300YQJRH 54ad2eac Stride-3, discard 3rd char Stride = 3, noise = decimal digit

Detection

YARA strings:

  • $func_name = "L300YQJRH" ascii wide
  • $au3_header = "AU3!EA06" ascii

Capa limitation: capa flags "autoit file limitation" and "compiled with AutoIt" but does not reach inside the script to identify the decoder.

See also