{"id":"29980d25febeb00552fbe51ecaab22d7","title":"AutoIt Malware — AutoIt Malware · 木马/恶意软件 · PE64","md5":"29980d25febeb00552fbe51ecaab22d7","sha256":"325f72a5df88f10ec123667268740c0b32a554db2cac9dbfdc0ddcb16a6edd43","family":"AutoIt Malware","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"Rust","file_format":"PE64","compiler":"Rust+AutoIt","published_at":"2026-08-09T16:00:00.000Z","summary":"该样本采用罕见的双层包装：Rust 编译的外壳 + 内嵌的 AutoIt 3.XX 加密脚本。AutoIt 脚本标识符 $XAU3! 和 AutoItSC_x64 段名确认了其身份。 核心恶意能力： 网络通信：WinINet (HttpOpenRequestW, HttpSendRequestW, InternetConnectW, InternetOpenUrlW) — HTTP/HTTPS C2 通信 网络探测：ICMP (IcmpCreateFile, IcmpSendEcho) — 网络扫描/探测 权限提升：AdjustTokenPrivileges — 获取系统特权 注册表操作：RegDeleteKeyExW — 注册表删除 用户配置：LoadUserProfileW + GetPrivateProfileStringW — 读取用户配置 文件操作：CopyFileExW, CreateFileW, DeleteFileW — 文件复制/创建/删除 系统信息：GetNativeSystemInfo — 系统架构检测 多线程：CreateThread — 并发执行 AutoIt 脚本状态：加密存储于 .text$lp00AutoItSC_x64 段，需 AutoIt3 反编译器提取。","url":"https://zseceye.com/report/29980d25febeb00552fbe51ecaab22d7","json_url":"https://zseceye.com/report/29980d25febeb00552fbe51ecaab22d7.json","html_url":"https://zseceye.com/report/29980d25febeb00552fbe51ecaab22d7","hash_urls":{"md5":"https://zseceye.com/hash/29980d25febeb00552fbe51ecaab22d7","sha256":"https://zseceye.com/hash/325f72a5df88f10ec123667268740c0b32a554db2cac9dbfdc0ddcb16a6edd43"},"search_urls":{"md5":"https://zseceye.com/?q=29980d25febeb00552fbe51ecaab22d7","sha256":"https://zseceye.com/?q=325f72a5df88f10ec123667268740c0b32a554db2cac9dbfdc0ddcb16a6edd43"},"sample_download_url":"https://zseceye.com/report/29980d25febeb00552fbe51ecaab22d7/sample","sample_filename":"325f72a5df88f10e.zip","iocs":[],"ips":[]}